Impact
Type confusion in the Compositing component of Google Chrome, affecting versions prior to 153.0.8010.47, enables a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page. The flaw arises from incorrect type handling that permits inappropriate conversion or misuse of object types, classified as CWE-843. Attackers could leverage this to run malicious code, potentially bypassing sandbox protections and compromising system integrity.
Affected Systems
Google Chrome users running versions before 153.0.8010.47 are vulnerable. The affected product is Google Chrome, a web browser distributed by Google. No specific operating system restrictions were noted; the vulnerability applies across all platforms supported by the affected Chrome releases.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity level. The EPSS score of <1% indicates that, as of the latest data, the probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious HTML page served over the network or local file that the user views, enabling the type confusion on load and allowing execution of arbitrary code. Successful exploitation requires only that the user renders the crafted page while Chrome is running.
OpenCVE Enrichment
Debian DLA
Debian DSA