Impact
The vulnerability is a type confusion flaw in V8, the JavaScript engine used by Google Chrome. A malicious HTML page can trigger the bug, allowing an attacker to execute arbitrary code inside Chrome's sandbox. This flaw corresponds to CWE-843. The attacker can run code with the privileges of the sandboxed renderer process, potentially leading to compromise of the host system if the sandbox is bypassed.
Affected Systems
Google Chrome versions prior to 152.0.7977.82 are affected. The issue was addressed in the stable channel update released on September 2026. Systems running earlier versions should update to 152.0.7977.82 or a later patch.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is listed in the CISA KEV catalog. The CVSS score of 8.8 indicates high severity. The attack vector is remote via a crafted HTML page that a user would need to open; consequently, successful exploitation requires the victim to view a malicious page. While it allows code execution, the impact is limited to the sandboxed renderer until a sandbox escape is achieved. Nevertheless, the potential for privilege escalation warrants prompt patching.
OpenCVE Enrichment
Debian DLA
Debian DSA