# CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')

**KEV-linked**

> As of 2026-10-05, CWE-843 (Type Confusion) underlies 22 CVEs tracked by Threadlinqs, 11 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 38 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-843?

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

When the product accesses the resource using an incompatible type, this could trigger logical errors because the resource does not have expected properties. In languages without memory safety, such as C and C++, type confusion can lead to out-of-bounds memory access. While this weakness is frequently associated with unions when parsing data with many different embedded object types in C, it can be present in any application that can interpret the same variable or memory location in multiple ways. This weakness is not unique to C and C++. For example, errors in PHP applications can be triggered by providing array parameters when scalars are expected, or vice versa. Languages such as Perl, which perform automatic conversion of a variable of one type when it is accessed as if it were another type, can also contain these issues.

CWE-843 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: C; Language: C++.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/843.html) (CWE-843 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Availability, Integrity, Confidentiality** — Read Memory, Modify Memory, Execute Unauthorized Code or Commands, DoS: Crash, Exit, or Restart. When a memory buffer is accessed using the wrong type, it could read or write memory out of the bounds of the buffer, if the allocated buffer is smaller than the type that the code is attempting to access, leading to a crash and possibly code execution.

_Source: MITRE CWE, common consequences._

## How CWE-843 is exploited in the wild

Threadlinqs maps 22 CVEs to CWE-843, published between 2017-04-27 and 2026-09-29. 11 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 critical, 19 high, 1 medium. The highest EPSS score in the set is 96.9% (CVE-2017-8291), the modelled probability of exploitation in the next 30 days. 38 tracked threats reference CWE-843 directly or through a CVE it covers; the most recent is “Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)” (2026-09-30). Affected products concentrate in Google (10), Microsoft (8), Apple (5), among 13 vendors in total.

## Vulnerabilities (CVEs)

All 22 CVEs mapped to CWE-843, CISA KEV first, then by CVSS score.

- [CVE-2024-7971](https://intel.threadlinqs.com/cve/CVE-2024-7971) — CISA KEV · CVSS 9.6 critical · EPSS 1.0% · published 2024-08-21
- [CVE-2023-4762](https://intel.threadlinqs.com/cve/CVE-2023-4762) — CISA KEV · CVSS 8.8 high · EPSS 63.5% · published 2023-09-05
- [CVE-2023-2033](https://intel.threadlinqs.com/cve/CVE-2023-2033) — CISA KEV · CVSS 8.8 high · EPSS 25.1% · published 2023-04-14
- [CVE-2023-3079](https://intel.threadlinqs.com/cve/CVE-2023-3079) — CISA KEV · CVSS 8.8 high · EPSS 2.1% · published 2023-06-05
- [CVE-2026-85046](https://intel.threadlinqs.com/cve/CVE-2026-85046) — CISA KEV · CVSS 8.8 high · EPSS 1.1% · published 2026-09-03
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222) — CISA KEV · CVSS 8.8 high · EPSS 0.6% · published 2024-01-23
- [CVE-2022-42856](https://intel.threadlinqs.com/cve/CVE-2022-42856) — CISA KEV · CVSS 8.8 high · EPSS 0.1% · published 2022-12-15
- [CVE-2023-23529](https://intel.threadlinqs.com/cve/CVE-2023-23529) — CISA KEV · CVSS 8.8 high · EPSS 0.0% · published 2023-02-27
- [CVE-2025-6554](https://intel.threadlinqs.com/cve/CVE-2025-6554) — CISA KEV · CVSS 8.1 high · EPSS 0.9% · published 2025-06-30
- [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291) — CISA KEV · CVSS 7.8 high · EPSS 96.9% · published 2017-04-27
- [CVE-2026-21519](https://intel.threadlinqs.com/cve/CVE-2026-21519) — CISA KEV · CVSS 7.8 high · EPSS 4.5% · published 2026-02-10
- [CVE-2026-22104](https://intel.threadlinqs.com/cve/CVE-2026-22104) — CVSS 9.8 critical · EPSS 91.2% · published 2026-02-20
- [CVE-2026-102299](https://intel.threadlinqs.com/cve/CVE-2026-102299) — CVSS 8.8 high · published 2026-09-29
- [CVE-2026-102323](https://intel.threadlinqs.com/cve/CVE-2026-102323) — CVSS 8.8 high · published 2026-09-29
- [CVE-2026-14431](https://intel.threadlinqs.com/cve/CVE-2026-14431) — CVSS 8.8 high · published 2026-07-01
- [CVE-2025-62554](https://intel.threadlinqs.com/cve/CVE-2025-62554) — CVSS 8.4 high · EPSS 0.3% · published 2025-12-09
- [CVE-2026-40364](https://intel.threadlinqs.com/cve/CVE-2026-40364) — CVSS 8.4 high · EPSS 0.1% · published 2026-05-12
- [CVE-2026-26110](https://intel.threadlinqs.com/cve/CVE-2026-26110) — CVSS 8.4 high · EPSS 0.1% · published 2026-03-10
- [CVE-2026-33824](https://intel.threadlinqs.com/cve/CVE-2026-33824) — CVSS 8.4 high · EPSS 0.0% · published 2026-04-14
- [CVE-2026-5946](https://intel.threadlinqs.com/cve/CVE-2026-5946) — CVSS 7.5 high · EPSS 0.0% · published 2026-05-20
- [CVE-2026-9117](https://intel.threadlinqs.com/cve/CVE-2026-9117) — CVSS 7.5 high · EPSS 0.0% · published 2026-05-20
- [CVE-2026-10702](https://intel.threadlinqs.com/cve/CVE-2026-10702) — CVSS 4.3 medium · EPSS 0.5% · published 2026-06-02

## Affected vendors

- [Google](https://intel.threadlinqs.com/vendors/google) — 10 CVEs
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 8 CVEs
- [Apple](https://intel.threadlinqs.com/vendors/apple) — 5 CVEs
- [Debian](https://intel.threadlinqs.com/vendors/debian) — 3 CVEs
- **Couchbase** — 2 CVEs
- [Fedoraproject](https://intel.threadlinqs.com/vendors/fedoraproject) — 2 CVEs
- [Linux](https://intel.threadlinqs.com/vendors/linux) — 2 CVEs
- **Artifex** — 1 CVE
- [ISC](https://intel.threadlinqs.com/vendors/isc) — 1 CVE
- **MediaTek** — 1 CVE
- [Mozilla](https://intel.threadlinqs.com/vendors/mozilla) — 1 CVE
- **Qualcomm** — 1 CVE

## Threat activity

38 tracked threats cite CWE-843; the 25 most recent are listed.

- [Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)](https://intel.threadlinqs.com/threat/TL-2026-2803) — CRITICAL · 2026-09-30
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP Malware](https://intel.threadlinqs.com/threat/TL-2026-2681) — CRITICAL · 2026-09-27
- [Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37)](https://intel.threadlinqs.com/threat/TL-2026-2662) — MEDIUM · 2026-09-26
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — CRITICAL · 2026-09-13
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)](https://intel.threadlinqs.com/threat/TL-2026-2407) — CRITICAL · 2026-09-08
- [Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusion](https://intel.threadlinqs.com/threat/TL-2026-2326) — HIGH · 2026-09-04
- [Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Enables Sandbox Escape and RCE on Host](https://intel.threadlinqs.com/threat/TL-2026-2121) — CRITICAL · 2026-08-23
- [Critical Type Confusion in isolated-vm ExternalCopy Enables Guest-to-Host Sandbox Escape and RCE (GHSA-864f-rcv7-6rh4)](https://intel.threadlinqs.com/threat/TL-2026-2084) — CRITICAL · 2026-08-20
- [Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)](https://intel.threadlinqs.com/threat/TL-2026-1908) — CRITICAL · 2026-08-06
- [Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)](https://intel.threadlinqs.com/threat/TL-2026-1605) — HIGH · 2026-07-22
- [IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499 "GhostLock") Demonstrated Against Android 17](https://intel.threadlinqs.com/threat/TL-2026-1477) — HIGH · 2026-07-18
- [Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure (CVE-2026-15899 through CVE-2026-15905)](https://intel.threadlinqs.com/threat/TL-2026-1501) — HIGH · 2026-07-18
- [Chrome 150 Security Update Fixes 15 Vulnerabilities Including Two Critical Use-After-Free Flaws in Ozone (CVE-2026-15764, CVE-2026-15765)](https://intel.threadlinqs.com/threat/TL-2026-1368) — CRITICAL · 2026-07-15
- [Microsoft's MDASH AI Scanning Harness Uncovers 16 Windows CVEs, Including Four Critical RCE Flaws in TCP/IP, IKEv2, Netlogon, and DNS](https://intel.threadlinqs.com/threat/TL-2026-1184) — CRITICAL · 2026-07-10
- [BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege Dominates (CVE-2025-55241, CVE-2025-62557, CVE-2025-62554)](https://intel.threadlinqs.com/threat/TL-2026-1060) — HIGH · 2026-07-02
- [Chrome 151 Security Update Patches 382 Vulnerabilities, Including 15 Critical Memory-Corruption Flaws (CVE-2026-13774 to CVE-2026-13788)](https://intel.threadlinqs.com/threat/TL-2026-1026) — CRITICAL · 2026-07-01
- [CVE-2023-36802 (Windows Streaming Service Proxy mskssrv.sys) — Full Exploitation Chain Without NtQuery*/PreviousMode Shortcuts](https://intel.threadlinqs.com/threat/TL-2026-1539) — HIGH · 2026-06-24
- [Multiple Vulnerabilities in Firefox 152 Enable Remote Code Execution and Sandbox Escape (MFSA 2026-57)](https://intel.threadlinqs.com/threat/TL-2026-0855) — HIGH · 2026-06-18
- [Google Chrome 149.0.7827.53 — 429 Vulnerabilities Patched (22 Critical); Critical ANGLE/GPU Memory-Safety Sandbox-Escape Chain (CVE-2026-10881 / CVE-2026-10883 / CVE-2026-10898)](https://intel.threadlinqs.com/threat/TL-2026-0720) — CRITICAL · 2026-06-08
- [BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)](https://intel.threadlinqs.com/threat/TL-2026-0599) — HIGH · 2026-05-27
- [art-template npm Supply Chain Backdoor — Coruna Respawned iOS Safari Watering-Hole Exploit Kit (v4.13.3/4.13.5/4.13.6, CVE-2024-23222)](https://intel.threadlinqs.com/threat/TL-2026-0568) — CRITICAL · 2026-05-22
- [CISA KEV Catalog Adds Seven Vulnerabilities (May 20, 2026) — Microsoft Defender CVE-2026-41091 (EoP) and CVE-2026-45498 (DoS) Headline Active Exploitation Batch](https://intel.threadlinqs.com/threat/TL-2026-0545) — HIGH · 2026-05-21
- [Google Chrome Stable 148.0.7778.178/179 — CVE-2026-9111 WebRTC Use-After-Free RCE & CVE-2026-9110 UI Inappropriate Implementation (16 CVEs Patched)](https://intel.threadlinqs.com/threat/TL-2026-0554) — CRITICAL · 2026-05-21
- [Microsoft May 2026 Patch Tuesday — 137 CVEs, 31 Critical (16 RCE) Including CVE-2026-41089 Pre-Auth Netlogon Stack Overflow on Domain Controllers](https://intel.threadlinqs.com/threat/TL-2026-0504) — HIGH · 2026-05-12
- [Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited In-The-Wild, CVE-2026-33825 Defender EoP Public PoC, CVE-2026-33824 IKE RCE CVSS 9.8, CVE-2026-33827 TCP/IP Wormable RCE)](https://intel.threadlinqs.com/threat/TL-2026-0391) — CRITICAL · 2026-04-19

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-704](https://cwe.mitre.org/data/definitions/704.html)
- [CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer](https://intel.threadlinqs.com/cwe/CWE-119)

Canonical: https://intel.threadlinqs.com/cwe/CWE-843
Source definition: https://cwe.mitre.org/data/definitions/843.html
Detection rules and IOCs for threats exploiting CWE-843 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
