CVE-2026-91709
8.8Google · Chrome
A type confusion vulnerability in the ServiceWorker component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity type confusion vulnerability in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution through malicious web content.
Vulnerability
The flaw is a type confusion vulnerability (CWE-843) located within the ServiceWorker implementation. An unauthenticated remote attacker can trigger this condition by enticing a user to visit a specially crafted HTML page, leading to arbitrary code execution within the browser sandbox.
Business impact
The ability for a remote attacker to execute arbitrary code poses a significant risk to organizational security. Successful exploitation could lead to full compromise of the local browser environment, potentially allowing for data theft, session hijacking, or the deployment of further malicious payloads. With a CVSS score of 8.8, this vulnerability is classified as High and warrants immediate attention to prevent lateral movement or unauthorized access.
Remediation
Immediate Action: Update all Google Chrome instances to version 153.0.8010.47 or later to incorporate the vendor-supplied security patch.
Proactive Monitoring: Monitor endpoint logs for unusual browser activity or unexpected process execution patterns that may indicate a sandbox escape attempt.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block malicious script execution within the browser process.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS severity and the potential for arbitrary code execution, this vulnerability represents a significant risk to end-user workstations. Organizations should prioritize the deployment of the Chrome update across all managed assets to ensure the ServiceWorker component is patched. Failure to update may expose users to browser-based attacks that bypass standard security boundaries.
More Google CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section