CVE-2026-91715

8.8

Google · Chrome

A type confusion vulnerability in the ServiceWorker component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A critical type confusion vulnerability in Google Chrome allows remote code execution, posing a significant risk to user systems and data integrity.

Vulnerability

The flaw exists within the ServiceWorker component due to type confusion (CWE-843). An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted HTML page, leading to arbitrary code execution within the browser sandbox.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve remote code execution on the host system within the context of the browser. This could result in full compromise of the user session, unauthorized access to sensitive local data, or further exploitation of the underlying operating system. Given the high CVSS score of 8.8, this vulnerability represents a severe threat to business continuity and data confidentiality.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.47 or later as mandated by the vendor security advisory.

Proactive Monitoring: Monitor endpoint logs for suspicious browser process activity or unexpected child processes spawned by Google Chrome.

Compensating Controls: Ensure that browser security settings are strictly enforced via Group Policy or MDM solutions, and encourage users to utilize updated software to benefit from sandbox security improvements.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a substantial risk due to the potential for remote code execution. Security teams should prioritize the deployment of the 153.0.8010.47 update across all environments to ensure browser security and prevent potential exploitation. Failure to patch promptly leaves systems exposed to malicious web content designed to leverage this type confusion flaw.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources