PT-2026-93127 · Google · Google Chrome
CVE-2026-91709
·
Published
2026-09-15
·
Updated
2026-09-18
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 153.0.8010.47
Description
A type confusion issue exists in the ServiceWorker component. This occurs when the system incorrectly identifies the data type of an object, which can be leveraged by a remote attacker to execute arbitrary code within the sandbox by enticing a user to visit a specially crafted HTML page.
Recommendations
Update to version 153.0.8010.47 or later.
Fix
RCE
DoS
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome