Description
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution within the browser sandbox
Action: Immediate Patch
AI Analysis

Impact

A type confusion flaw was found in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox. The vulnerability arises when the engine misidentifies an object type during script execution, enabling maliciously crafted HTML pages to control privilege escalation within the sandbox. The effect is the ability to run code with the same privileges as the sandboxed browser process.

Affected Systems

Google Chrome version 153.0.8010.36 or earlier are impacted. Any system that installs an affected Chrome version without updating to 153.0.8010.36 or later is vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8 and can be triggered remotely through a crafted web page, meaning an attacker only needs the user to visit a malicious site. The EPSS score is < 1%, indicating a low but non‑zero exploitation probability, and the flaw is not listed in CISA’s KEV catalog, but the high severity and the ease of exploitation through standard browsing paths suggest strong potential for real-world attacks. Immediate patching is required to mitigate this risk.

Generated by OpenCVE AI on September 9, 2026 at 15:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Chrome update to version 153.0.8010.36 or newer to eliminate the type confusion issue.
  • If an update cannot be performed immediately, restrict users from accessing untrusted or unknown web sites that could serve malicious HTML content in environments where Chrome is still deployed.
  • Enable Chrome's enterprise safety features, such as safe browsing and site isolation, to provide additional layers of protection while awaiting the official update.

Generated by OpenCVE AI on September 9, 2026 at 15:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Type confusion in V8 enables remote code execution in Chrome chromium-browser: chromium-browser: Type confusion in V8
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Type confusion in V8 enables remote code execution in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:30.893Z

Reserved: 2026-09-08T22:42:38.714Z

Link: CVE-2026-87612

cve-icon Vulnrichment

Updated: 2026-09-09T12:54:57.090Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:19.310

Modified: 2026-09-10T04:18:28.583

Link: CVE-2026-87612

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T00:09:37Z

Links: CVE-2026-87612 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:00:06Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')