Description
Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A type confusion bug in Chrome’s Rust components on Windows allows a remote attacker to send a specially crafted HTML page that can bypass the sandbox and execute code with elevated privileges, matching the CWE‑843 classification of unsafe type conversion.

Affected Systems

The flaw affects every user of Google Chrome on Windows running a version prior to 153.0.8010.36. Versions earlier than this release are vulnerable until an update containing the fix is installed.

Risk and Exploitability

The CVSS score of 9.6 reflects the high potential impact of this flaw, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote: an adversary must host or deliver a malicious HTML page that the vulnerable browser will render. No publicly available exploit is known, so current risk is moderate, but the severity warrants immediate action to prevent a potential catastrophic compromise.

Generated by OpenCVE AI on September 9, 2026 at 17:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Chrome update (153.0.8010.36 or newer).
  • Ensure Chrome’s sandbox is not disabled via command‑line flags or policy settings.
  • Disable or carefully review any third‑party extensions that could run in render processes or that expose network requests to the rendering engine.

Generated by OpenCVE AI on September 9, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Rust Type Confusion in Chrome on Windows Allows Remote Code Execution
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Rust Type Confusion in Chrome on Windows Allows Remote Code Execution

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:43.779Z

Reserved: 2026-09-08T22:39:33.031Z

Link: CVE-2026-87528

cve-icon Vulnrichment

Updated: 2026-09-09T13:29:39.704Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:10.110

Modified: 2026-09-10T04:18:24.127

Link: CVE-2026-87528

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T11:45:11Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')