Impact
A race condition in the V8 JavaScript engine of Google Chrome, discovered before version 155.0.8059.39, permits an attacker that can supply a crafted HTML page to trigger arbitrary code execution inside the browser's sandbox. The flaw allows the attacker to run code with the privileges granted to the sandbox, potentially enabling further compromise if the sandbox can be breached. Chromium classifies the vulnerability as Medium severity.
Affected Systems
All Google Chrome browsers on any platform with versions earlier than 155.0.8059.39, including the stable channel and builds based on V8 before that release.
Risk and Exploitability
The vulnerability can be exploited remotely by loading a malicious HTML page in the victim’s browser. It is not listed in the CISA KEV catalog and EPSS data are unavailable, suggesting a lower exploitation likelihood; however, the flaw is remotely triggerable without privileged credentials. Prompt patching is the most effective mitigation.
OpenCVE Enrichment