Executive brief
Google Chrome's CacheStorage API contains a type confusion vulnerability that allows attackers to execute arbitrary code within the browser sandbox by tricking users into visiting a malicious website. An attacker could leverage this to compromise the browser process, bypass security protections, and potentially access sensitive data or perform unauthorized actions on behalf of the user.
Technical details
A type confusion vulnerability exists in the CacheStorage implementation of Google Chrome prior to version 153.0.8010.47. The vulnerability allows a remote attacker to achieve arbitrary code execution within the browser sandbox through a specially crafted HTML page. This attack requires user interaction (visiting a malicious website) but no authentication. The type confusion likely results from improper type checking during object handling within the cache storage API, allowing an attacker to trigger memory safety issues or behavioral inconsistencies. The vulnerability has been patched in Chrome 153.0.8010.47 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Chrome 153.0.8010.47 and later