CVE-2026-93377
8.8Google · Chrome
A type confusion vulnerability in the V8 JavaScript engine of Google Chrome allows a remote attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A high severity type confusion vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution through social engineering.
Vulnerability
This flaw is a type confusion vulnerability within the V8 engine, which occurs when the software performs a pointer operation using an incompatible type. The vulnerability is exploitable by an unauthenticated remote attacker who lures a user into visiting a malicious HTML page.
Business impact
Successful exploitation of this vulnerability allows a remote attacker to execute arbitrary code within the browser sandbox, which can lead to a full compromise of the user session or the local machine. With a CVSS score of 8.8, this vulnerability poses a significant risk to organizational security, as it facilitates unauthorized access and potential data exfiltration.
Remediation
Immediate Action: Update all installations of Google Chrome to version 153.0.8010.52 or later to apply the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected child process spawning related to Chrome instances.
Compensating Controls: Utilize endpoint protection platforms to block known malicious domains and ensure that browser sandboxing features remain enabled and strictly enforced via group policy.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for arbitrary code execution and the high CVSS rating, administrators should prioritize the deployment of the Google Chrome update across all managed workstations. Users should be cautioned against clicking suspicious links or navigating to untrusted websites until the browser is fully updated to the patched version.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section