Description
Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a type confusion flaw in Google Chrome’s V8 JavaScript engine that can let a remote attacker cause the browser to execute arbitrary code within its sandbox. The flaw arises when the engine incorrectly handles type conversions, enabling malicious JavaScript embedded in a crafted HTML page to overwrite or corrupt internal data structures. If triggered, the attacker could run code at the privilege level granted to Chrome’s renderer process, potentially compromising confidential information or allowing further lateral movement on a victim’s system.

Affected Systems

Google Chrome versions prior to 155.0.8059.39 are susceptible. Any installation of Chrome below this build that renders untrusted HTML is potentially vulnerable and should be updated.

Risk and Exploitability

The CVSS base score of 8.8 classifies this as a high‑severity issue. With no EPSS score available, the exact exploitation likelihood cannot be quantified, but the attack vector is a remote HTTP request delivering crafted content, so a user navigating to a malicious site is a prerequisite. The flaw is not listed in the CISA KEV catalog, indicating that no widespread, verified exploitation has yet been reported, yet the severity warrants immediate attention.

Generated by OpenCVE AI on October 6, 2026 at 22:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to 155.0.8059.39 or later to receive the V8 engine fix
  • Deploy a browser policy or Content Security Policy to restrict execution of untrusted JavaScript or to force sandbox isolation for all loaded content
  • Educate users to avoid visiting untrusted sites and monitor for phishing or malicious sites that could host the crafted HTML exploit

Generated by OpenCVE AI on October 6, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome V8 Enables Remote Code Execution

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-843
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T19:45:33.719Z

Reserved: 2026-10-06T16:35:50.833Z

Link: CVE-2026-106341

cve-icon Vulnrichment

Updated: 2026-10-06T19:40:45.493Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:02.570

Modified: 2026-10-06T20:17:23.007

Link: CVE-2026-106341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:15:06Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')