CVE-2026-93377
chrome: Access of Resource Using Incompatible Type ('Type Confusion') (CVE-2026-93377)
highEPSS 0.4%
Description
Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
googlechrome
153.0.8010.52fixed from 153.0.8010.52Metrics
Show all metrics
Severity
high
84.36
no public PoC known
8.8
Published
2026-09-30 20:25 UTC
CWE-843
Weakness classes (CWE)
CWE-843Base
Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-21 13:02 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 153.0.8010.52
- Reference Type: Chrome: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html Types: Release Notes, Vendor Advisory
- Reference Type: Chrome: https://issues.chromium.org/issues/560121552 Types: Permissions Required
- CVE Modified2026-09-19 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-93377","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-93377","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-09-18 14:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- SSVC: {"id":"CVE-2026-93377","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-17 21:17 UTC· chrome-cve-admin@google.com
- Description: Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CWE: CWE-843
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93377.json">CVE-2026-93377</a>
- Reference: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html