Impact
Based on the description, it is inferred that an oversight in the V8 JavaScript engine in Google Chrome prior to version 149.0.7827.53 permits a remote attacker to induce heap corruption by persuading a user to perform certain UI gestures when accessing a specifically crafted HTML page. The resulting heap damage could lead to arbitrary code execution or other destructive behavior, as indicated by Chromium’s high severity rating and the CWE‑416 association.
Affected Systems
All users running Google Chrome (desktop and potentially mobile) dated before 149.0.7827.53 are vulnerable, regardless of operating system, because the flaw resides in the core V8 engine used by every build of the browser.
Risk and Exploitability
Based on the description, it is inferred that the flaw requires user interaction with a malicious page and that the potential for remote code execution exists. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no documented public exploitation to date. Because of the user‑interaction prerequisite, the risk is moderate to high if an attacker can influence a user to activate the required gestures.
OpenCVE Enrichment