Impact
An out-of-bounds memory access occurs in the V8 JavaScript engine of Google Chrome prior to version 144.0.7559.59, allowing a malicious actor to craft an HTML page that, when rendered by the victim’s browser, may corrupt internal objects. The vulnerability is documented as a buffer overflow (CWE‑125) and a denial of bounds (CWE‑787), both of which can facilitate arbitrary code execution or denial of service on the affected system.
Affected Systems
Google Chrome browsers running on Windows, macOS, and Linux are vulnerable when their version is earlier than 144.0.7559.59. The defect is present in all major operating systems that support Chrome, as indicated by the associated CPE entries.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, reflecting high severity, but the EPSS score of less than 1% signals a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker delivering a crafted HTML page to the victim; this inference is drawn because the official description states that the flaw can be triggered via a crafted HTML page, though the exact delivery method is not explicitly detailed.
OpenCVE Enrichment
Debian DSA