Executive brief
Google Chromium's V8 JavaScript engine contains a type confusion flaw that allows attackers to execute arbitrary code within the browser sandbox by sending a specially crafted HTML page. This vulnerability affects all major Chromium-based browsers including Chrome, Edge, and Opera, putting users at risk of account compromise, malware infection, and data theft.
Technical details
A type confusion vulnerability exists in Google Chromium's V8 JavaScript engine that allows remote code execution within the browser's sandbox. The vulnerability stems from improper type checking in the V8 engine, enabling an attacker to manipulate object types to bypass security checks. An attacker can exploit this flaw by crafting a malicious HTML page and enticing a user to visit it; no special privileges or authentication are required. Successful exploitation allows arbitrary code execution within the sandbox, from which further attacks on the system or user data may be mounted. The vulnerability is known to be exploited in the wild as of the publication date, making patching urgent.
Affected products
- Google Chromium <unknown>
- Google Chrome <unknown>
- Microsoft Edge <unknown>
- Opera Opera Browser <unknown>
Timeline
- 2026-09-04: disclosed
- 2026-09-04: exploited: Confirmed exploited in the wild