AI analysis
Google Chrome versions prior to 153.0.8010.36 contain a type confusion flaw in the V8 JavaScript engine (CWE-843), rated High severity with a CVSS 3.1 score of 8.8. A remote attacker can trigger it by luring a user to a crafted HTML page, causing V8 to mishandle object types and corrupt memory during script execution. Successful exploitation allows the attacker to execute arbitrary code inside the browser's sandbox, which limits the immediate impact to the sandbox's privileges unless the attacker chains it with a separate sandbox escape. Anyone running an affected Chrome build is exposed, which in practice spans nearly the browser's entire multi-billion-user install base. Related coverage of the Chrome 153 release (230 security fixes) reports a zero-day exploited in the wild, while the CVE record itself lists no public PoC, no CISA KEV entry, and a modest 0.2% EPSS probability of exploitation in the next 30 days.
What to do: Update Chrome to 153.0.8010.36 or later immediately and confirm the patched version via chrome://settings/help; enterprise administrators should push the update through their browser management tooling and force relaunches so the fix takes effect. Because exploitation is reported in the wild in connection with the Chrome 153 release, treat this as a priority patch, and monitor for follow-on sandbox-escape exploits since this flaw alone grants only sandboxed code execution.
Affected
| google chrome | all versions prior to 153.0.8010.36 |
Estimated exposure
mass≈3+ billion users (Chrome's global install base; every build before 153.0.8010.36 is vulnerable) — Chrome is the world's most widely used desktop browser with a global user base measured in billions, and all installations running versions earlier than 153.0.8010.36 are affected.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.