Executive brief
Google Chrome's V8 JavaScript engine contains a type confusion flaw that allows remote attackers to execute arbitrary code within the browser sandbox by tricking users into visiting a malicious website. This could allow attackers to steal sensitive browser data, credentials, or use the compromised browser as a foothold for further attacks on the user's system.
Technical details
A type confusion vulnerability exists in V8, Google Chrome's JavaScript engine, which allows remote attackers to execute arbitrary code within the sandbox. The vulnerability is triggered via a crafted HTML page and leverages social engineering to trick users into visiting malicious content. The attack requires user interaction (visiting a website) but does not require authentication. An attacker can achieve code execution within the Chrome sandbox, potentially leading to data exfiltration or further system compromise. The vulnerability was patched in Chrome 153.0.8010.52/53.
Affected products
- Google Chrome prior to 153.0.8010.52
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Fixed in Chrome 153.0.8010.52/53