Impact
This vulnerability is a type confusion flaw in Google Chrome’s V8 JavaScript engine that can let a remote attacker cause the browser to execute arbitrary code within its sandbox. The flaw arises when the engine incorrectly handles type conversions, enabling malicious JavaScript embedded in a crafted HTML page to overwrite or corrupt internal data structures. If triggered, the attacker could run code at the privilege level granted to Chrome’s renderer process, potentially compromising confidential information or allowing further lateral movement on a victim’s system.
Affected Systems
Google Chrome versions prior to 155.0.8059.39 are susceptible. Any installation of Chrome below this build that renders untrusted HTML is potentially vulnerable and should be updated.
Risk and Exploitability
The CVSS base score of 8.8 classifies this as a high‑severity issue. With no EPSS score available, the exact exploitation likelihood cannot be quantified, but the attack vector is a remote HTTP request delivering crafted content, so a user navigating to a malicious site is a prerequisite. The flaw is not listed in the CISA KEV catalog, indicating that no widespread, verified exploitation has yet been reported, yet the severity warrants immediate attention.
OpenCVE Enrichment