Type confusion in Chrome V8 allows sandbox code execution
Type confusion in Chrome's V8 engine lets remote attackers run arbitrary code inside the browser sandbox via a crafted HTML page. Actively exploited; update to 152.0.7977.82.
- Vendor
- Product
- Chrome (before 152.0.7977.82)
- CVSS
- 8.8
- EPSS (exploit probability)
- N/A
- Status
- exploited-in-wild
- Published
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allows a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page. Google confirmed active exploitation in the wild on September 4, 2026.
Security researcher Salvatore Gulizia (Serotav) reported the flaw on August 4, 2026. Google addressed it in Chrome 152.0.7977.82 for Linux and 152.0.7977.82/.83 for Windows and macOS.
Patch: Update Chrome to 152.0.7977.82 or later. Go to Help > About Google Chrome to trigger the update.
