Impact
Race condition in V8 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. The flaw enables code execution without privilege escalation, compromising confidentiality, integrity, and availability at the process level. The vulnerability is classified as CWE‑362.
Affected Systems
All instances of Google Chrome before version 155.0.8059.39 on any platform that uses V8 for rendering are affected.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. The likely attack vector is delivering a malicious HTML page that the browser processes, which can be done over the network or via local file access. Successful exploitation would occur in the context of the browser’s sandbox, potentially enabling further lateral movement if the sandbox is compromised.
OpenCVE Enrichment