Executive brief
Google Chrome's V8 JavaScript engine contains a type confusion vulnerability that allows a remote attacker to read memory within the browser's sandbox by opening a specially crafted HTML page. While contained within the sandbox, this memory leak could expose sensitive data processed by the browser and weaken the browser's security isolation. Users are vulnerable simply by visiting a malicious website.
Technical details
This vulnerability is a type confusion flaw in V8, Google Chrome's JavaScript engine, that enables an attacker to read arbitrary memory within the renderer process sandbox. The root cause lies in V8's type system, where improper handling of type checks allows crafted JavaScript code to access memory regions it should not have access to. The attack requires no authentication and is triggered simply by a remote user visiting a malicious HTML page; user interaction is limited to normal browsing. An attacker can leak sensitive data resident in the browser's memory, potentially including session tokens, encryption keys, or other confidential information, though exploitation is restricted to the sandbox boundary. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8–9, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Patched in Chrome 153.0.8010.36