Description
Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A type confusion flaw in the Developer Tools of Google Chrome before version 152.0.7977.65 allows a remote attacker to run arbitrary code within the Chrome sandbox. The issue arises when a crafted HTML page is loaded, exploiting a mismatch between expected and actual data types. The vulnerability grants attackers code execution privileges that bypass normal sandbox restrictions, potentially enabling disclosure or modification of local data, execution of system commands, or other malicious actions confined to the browser context.

Affected Systems

Google Chrome users running any release prior to 152.0.7977.65 are affected. The issue was addressed in the August 2026 update that ships Chrome 152.0.7977.65. All desktop environments that rely on Chrome’s stable channel are potentially vulnerable if not updated.

Risk and Exploitability

The flaw presents a Remote Code Execution risk with a CVSS score of 8.8 indicating high severity. The EPSS score is < 1%, and the absence of a CISA KEV listing suggests limited observed exploitation but does not eliminate the threat. Attackers would likely employ social engineering to lure a victim into visiting a malicious HTML page, enabling the exploit via the browser’s DevTools component. Users who regularly visit untrusted sites or allow unverified extensions are at greater risk.

Generated by OpenCVE AI on August 26, 2026 at 14:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 152.0.7977.65 or later to apply the published patch
  • Configure browser settings or group policy to disable or restrict access to DevTools when not needed
  • Implement content‑security‑policy headers that block loading of suspect HTML content to reduce the chance of social‑engineering attacks

Generated by OpenCVE AI on August 26, 2026 at 14:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via DevTools Type Confusion in Google Chrome

Wed, 26 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via DevTools Type Confusion in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:56:30.855Z

Reserved: 2026-08-25T06:12:02.053Z

Link: CVE-2026-79227

cve-icon Vulnrichment

Updated: 2026-08-26T12:55:57.473Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:16.857

Modified: 2026-08-31T18:22:32.960

Link: CVE-2026-79227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T15:00:07Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')