Impact
Based on the description, it is inferred that an oversight in the V8 JavaScript engine in Google Chrome prior to version 149.0.7827.53 permits a remote attacker to induce heap corruption by persuading a user to perform certain UI gestures when accessing a specifically crafted HTML page. The resulting heap damage could lead to arbitrary code execution or other destructive behavior, as indicated by Chromium’s high severity rating and the CWE-122 and CWE-787 association.
Affected Systems
All users running Google Chrome (desktop and potentially mobile) dated before 149.0.7827.53 are vulnerable, regardless of operating system, because the flaw resides in the core V8 engine used by every build of the browser.
Risk and Exploitability
Based on the description, the flaw requires user interaction with a malicious page and has the potential for remote code execution. The EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, showing no documented public exploitation to date. The CVSS score of 8.8 reflects a high severity. Because of the user‑interaction prerequisite, the risk remains moderate to high if an attacker can influence a user to perform the required gestures.
OpenCVE Enrichment
Debian DSA