CVE-2026-91741
8.8Google · Chrome
A type confusion vulnerability in Google Chrome's CacheStorage component allows a remote, unauthenticated attacker to execute arbitrary code within the sandbox using a crafted HTML page.
Executive summary
A critical type confusion vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution via crafted web content.
Vulnerability
The vulnerability is a type confusion flaw (CWE-843) located within the CacheStorage component. It can be triggered by an unauthenticated remote attacker who lures a user to visit a malicious website containing a crafted HTML page.
Business impact
Successful exploitation of this flaw allows for arbitrary code execution within the browser sandbox, which poses a significant threat to data confidentiality, integrity, and system availability. Given the CVSS score of 8.8, this vulnerability is classified as high severity, indicating that attackers could potentially compromise user sessions, steal sensitive browser data, or facilitate further system exploitation.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.47 or later to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint logs for unusual browser activity or unexpected process execution patterns that may indicate an attempt to exploit the browser sandbox.
Compensating Controls: Utilize endpoint protection platforms that provide browser isolation or advanced threat detection to mitigate the impact of malicious web content if patching is delayed.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates immediate action, as browser-based code execution flaws are frequently targeted for initial access. IT administrators should prioritize the deployment of the 153.0.8010.47 update across all managed environments to eliminate the risk of remote compromise.
More Google CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section