Impact
A type‑confusion flaw in the V8 JavaScript engine of Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox by serving a specially crafted HTML page. This vulnerability is classified as high severity in Chromium’s own assessment and could lead to compromise of the user's machine if the sandbox escapes. The flaw involves a mismatch between expected and actual object types, enabling the attacker to manipulate the engine’s behavior and run code that the sandbox normally rejects.
Affected Systems
All installations of Google Chrome that use the V8 engine and are running a version prior to 154.0.8037.97 are impacted. No specific version ranges beyond this lower bound are listed; the vendor does not provide a detailed list of affected releases, so any older stable channel build is considered vulnerable.
Risk and Exploitability
Chromium assigns this bug a high severity, but no EPSS score is available and it is not listed in CISA’s KEV catalog. The exploit requires the attacker to serve a malicious HTML page that a user opens or visits; thus the attack vector is web‑based and the impact is limited to the local user session unless the user also runs privileged extensions or plugins. Given the high severity and the lack of mitigation, the risk to systems that open untrusted content is significant.
OpenCVE Enrichment