Executive brief
Google Chrome's V8 JavaScript engine contained a type confusion vulnerability that allowed attackers to execute arbitrary code within the browser's security sandbox by serving a specially crafted web page. This could lead to complete compromise of user data and operations running within the browser, including access to sensitive information stored in web applications and local browser storage.
Technical details
A type confusion vulnerability in V8 (Chrome's JavaScript engine) allows remote code execution within the browser sandbox. The vulnerability is triggered via a crafted HTML page containing malicious JavaScript that exploits type confusion to corrupt memory and execute arbitrary code. The attack requires only network reachability and user interaction (visiting a malicious webpage); no authentication is required. An attacker can achieve code execution with the privileges of the browser process, potentially accessing user data, session tokens, and files accessible to the browser. The vulnerability was fixed in Chrome version 153.0.8010.36, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released