Impact
A type confusion flaw in the Developer Tools of Google Chrome before version 152.0.7977.65 allows a remote attacker to run arbitrary code within the Chrome sandbox. The issue arises when a crafted HTML page is loaded, exploiting a mismatch between expected and actual data types. The vulnerability grants attackers code execution privileges that bypass normal sandbox restrictions, potentially enabling disclosure or modification of local data, execution of system commands, or other malicious actions confined to the browser context.
Affected Systems
Google Chrome users running any release prior to 152.0.7977.65 are affected. The issue was addressed in the August 2026 update that ships Chrome 152.0.7977.65. All desktop environments that rely on Chrome’s stable channel are potentially vulnerable if not updated.
Risk and Exploitability
The flaw presents a Remote Code Execution risk with a CVSS score of 8.8 indicating high severity. The EPSS score is < 1%, and the absence of a CISA KEV listing suggests limited observed exploitation but does not eliminate the threat. Attackers would likely employ social engineering to lure a victim into visiting a malicious HTML page, enabling the exploit via the browser’s DevTools component. Users who regularly visit untrusted sites or allow unverified extensions are at greater risk.
OpenCVE Enrichment
Debian DLA
Debian DSA