Impact
A race condition exists within the V8 JavaScript engine used by Google Chrome versions prior to 155.0.8059.39. The flaw permits a remote attacker to craft an HTML page that, when loaded, causes the engine to execute arbitrary code inside the browser sandbox. This leads to memory corruption and the potential for arbitrary code execution, compromising the integrity and confidentiality of the affected system.
Affected Systems
Google Chrome browsers that have not applied the 155.0.8059.39 update are vulnerable. All platforms that ship this Chrome version, including Windows, macOS, and Linux desktop releases, are impacted until the patch is installed.
Risk and Exploitability
Exploit requires a user to load a maliciously crafted web page, implying a remote attack vector. The CVSS score of 8.8 indicates high severity and no EPSS information is available. The vulnerability is not presently listed in CISA’s KEV catalog, indicating no known exploitation in the wild yet, but the nature of the flaw suggests it could be actively leveraged if discovered by attackers.
OpenCVE Enrichment