Description
Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a type confusion error in Chrome’s bindings that enables a remote attacker to execute arbitrary code from a crafted HTML page. This flaw is classified as CWE-843 and grants code execution within the confines of the Chrome sandbox, thereby compromising the confidentiality, integrity, and potentially availability of the user’s data. The impact is high and can be triggered without any need for credentials or local access.

Affected Systems

Google Chrome versions prior to 149.0.7827.103 are affected. The fix is included in the 149.0.7827.103 release and later.

Risk and Exploitability

The exploit requires the victim to view a malicious HTML page, making it a remote, web‑based attack vector. While no EPSS score is available, the vulnerability is listed as high severity (CVSS 8.8) and is not yet in the CISA KEV catalog. Because the flaw allows code to run inside the sandbox, a successful exploit effectively gives the attacker equivalent privilege to the running Chrome instance. The absence of a public workaround means the only reliable mitigation is to apply the vendor’s patch. Users who cannot update are at elevated risk if they encounter malicious web content.

Generated by OpenCVE AI on June 9, 2026 at 03:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.103 or newer, where the type confusion bug has been fixed.
  • Ensure that Chrome’s sandbox is enabled and that the default site isolation settings remain active to contain any code that does manage to escape the browser context.
  • If an immediate upgrade is not possible, limit exposure by disabling JavaScript or using custom content‑settings policies for untrusted sites, and consider using an alternative browser without the affected code.

Generated by OpenCVE AI on June 9, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Tue, 09 Jun 2026 04:15:00 +0000

Type Values Removed Values Added
Title Type Confusion Exploit in Chrome Enables Remote Code Execution via Crafted HTML

Tue, 09 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Type Confusion Exploit in Chrome Enables Remote Code Execution via Crafted HTML

Tue, 09 Jun 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Mon, 08 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-09T03:56:00.629Z

Reserved: 2026-06-08T21:33:44.176Z

Link: CVE-2026-11662

cve-icon Vulnrichment

Updated: 2026-06-09T01:16:56.338Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T00:16:49.290

Modified: 2026-06-09T14:58:55.233

Link: CVE-2026-11662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T04:00:14Z

Weaknesses