Description
Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Race condition in the V8 engine of Google Chrome allows a remote attacker to run arbitrary code inside the sandbox by serving a crafted HTML page. The flaw is a classic data‑race condition that can be triggered when the browser parses concurrent scripting contexts. Because the sandbox is designed to isolate web content, an exploit would allow the attacker to escape this isolation and gain code execution capabilities on the host system.

Affected Systems

Google Chrome browsers prior to version 154.0.8037.57 are vulnerable. The issue exists across all desktop releases that use the V8 JavaScript engine before the mentioned update.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score is not available, so no current estimate of exploitation probability can be provided, but the vulnerability is listed as high in Chromium’s own severity taxonomy. The flaw is not yet recorded in CISA’s KEV catalog, so there are no known large‑scale exploits yet. Exploitation would likely occur through a malicious web page or infected content that a user opens in Chrome.

Generated by OpenCVE AI on September 29, 2026 at 22:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 154.0.8037.57 or later to obtain the fix for V8.
  • Ensure that Chrome’s built‑in sandboxing features remain enabled and that no policy disables the sandbox or related engine limits.
  • Monitor for and block known malicious web content that may contain crafted HTML designed to trigger this race condition.

Generated by OpenCVE AI on September 29, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6513-1 chromium security update
History

Tue, 29 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Race Condition in V8 Enables Remote Code Execution via Crafted HTML

Tue, 29 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-362
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T19:03:19.770Z

Reserved: 2026-09-22T05:07:02.494Z

Link: CVE-2026-95280

cve-icon Vulnrichment

Updated: 2026-09-29T18:52:12.095Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-29T18:17:19.393

Modified: 2026-09-29T20:17:28.810

Link: CVE-2026-95280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:30:19Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')