Impact
An inappropriate implementation in the V8 JavaScript engine of Google Chrome prior to the version 149.0.7827.53 permits a remote attacker to execute arbitrary code within the Chrome sandbox by delivering a crafted HTML page. Based on the description, it is inferred that the flaw requires no user interaction beyond viewing the page and can grant the attacker the privileges of the browser’s renderer process.
Affected Systems
The vulnerability affects all users running Google Chrome versions older than 149.0.7827.53 on desktop operating systems, including Windows, macOS, and Linux. The issue resides in the browser itself, so the impact is independent of the underlying OS and extends to any environment where the affected browser version is installed.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity rating. The EPSS score is below 1%, and the flaw is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. However, because the attack vector is purely remote and only requires a malicious web page to be opened, the potential for compromise remains significant for users who have not applied the latest patch.
OpenCVE Enrichment
Debian DSA