CVE-2026-91731
8.8Google · Chrome
A type confusion vulnerability in the Google Chrome Compositing component allows a remote attacker to execute arbitrary code within the sandbox via a crafted HTML page.
Executive summary
A high-severity type confusion vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution via malicious web content.
Vulnerability
This is a type confusion vulnerability (CWE-843) located in the Compositing component of the browser. The vulnerability can be triggered by an unauthenticated remote attacker who lures a user to visit a specially crafted HTML page.
Business impact
Successful exploitation permits a remote attacker to execute arbitrary code within the context of the Chrome sandbox. Given the CVSS score of 8.8, this poses a significant risk to organizational endpoints by potentially enabling data exfiltration, malware installation, or further lateral movement within the network if the sandbox is bypassed or chained with other exploits.
Remediation
Immediate Action: Update all Google Chrome installations to version 153.0.8010.47 or later as mandated by the vendor security release.
Proactive Monitoring: Review endpoint security logs for unusual browser activity or unexpected child process spawning originating from the Chrome executable.
Compensating Controls: Deploy endpoint protection solutions that monitor for malicious memory patterns and ensure that standard browser security features remain enabled.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
The severity of this vulnerability, combined with the ubiquity of Google Chrome in enterprise environments, necessitates immediate action. Administrators must prioritize the deployment of the 153.0.8010.47 update across all workstations to mitigate the risk of remote exploitation and ensure the integrity of the browser environment.
More Google CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section