Impact
An integer overflow in the V8 JavaScript engine of Google Chrome allows a remote attacker to run arbitrary code inside the browser’s sandbox when a user visits a specially crafted HTML page. The flaw can bypass the browser’s security restrictions and grants the attacker code‑execution privileges, matching CWE‑472 and CWE‑190.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 are affected. Users with any older stable build are vulnerable until a fix is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity, and its exploitability requires a user to visit or load a malicious web page. The EPSS score is < 1% and the flaw is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation yet. However, an attacker can leverage the issue over the network via crafted HTML content, making it a legitimate strategic threat.
OpenCVE Enrichment
Debian DSA