ZeroHour

CVE-2026-93377

mass

Type Confusion in V8 Allows Sandbox-Restricted Code Execution in Google Chrome

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-93377 is a type confusion flaw (CWE-843) in V8, the JavaScript engine used by Google Chrome. An attacker triggers it by convincing a user to open a specially crafted HTML page, meaning successful attacks require a social-engineering step such as a phishing link. If exploited, the attacker can execute arbitrary code within the Chrome renderer sandbox, limiting but not eliminating the impact of the compromise. All Chrome users running versions prior to 153.0.8010.52 are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time; the fix shipped in Chrome 153, which addressed 16 security issues in total.

What to do: Update Google Chrome to 153.0.8010.52 or later on all platforms (check via chrome://settings/help), and force the update across managed fleets using enterprise update policies. Because exploitation requires luring users to a crafted page, reinforce phishing awareness and verify the browser version on high-risk endpoints.

Affected
Google Chromeall versions prior to 153.0.8010.52
Estimated exposure
mass≈3+ billion Chrome users worldwide (browser market share of roughly 60-65%) — Chrome is the world's dominant desktop and mobile browser with several billion users per public market-share data, so effectively every Chrome installation below 153.0.8010.52 is exposed until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.