Impact
Type Confusion in the V8 JavaScript engine allows a remote attacker to execute arbitrary code inside the browser sandbox by manipulating type assumptions through a crafted HTML page. This flaw, identified as CWE‑843, undermines the integrity of the engine’s type system and can lead to full compromise of the confidentiality and integrity of the data processed by the browser. The impact is remote code execution within the sandboxed environment, potentially servable to further system compromise if sandbox barriers are bypassed.
Affected Systems
Users of Google Chrome prior to version 151.0.7922.72 on all supported platforms – Windows, macOS, and Linux – are affected. The Stable channel release before the July 2026 update contains the vulnerability. All desktop installations of Chrome that have not yet applied the update remain vulnerable. The flaw is not limited to any particular operating system or architecture; it applies uniformly across the supported Chrome builds.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. The EPSS score of < 1 % indicates a low predicted exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector most likely involves a malicious HTML document served over a network to a user’s browser; crafted scripts can trigger the type confusion and launch code execution inside the sandbox. Because the code runs under the restricted privileges of the sandbox, the immediate risk is containment, but a sandbox escape could elevate the impact to full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA