Impact
An incorrect implementation in V8, the JavaScript engine used by Google Chrome, permits a remote attacker to run arbitrary code inside the browser’s sandbox when a specially crafted HTML page is loaded. The flaw is a buffer overflow (CWE‑119) combined with a code‑injection vulnerability (CWE‑94) that allows arbitrary code execution inside a sandboxed process.
Affected Systems
All installations of Google Chrome that include a V8 engine version older than 150.0.7871.46 are affected. Users running any build prior to 150.0.7871.46 could be at risk if they visit a malicious page.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity remote code execution flaw. The EPSS score of less than 1% shows a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a malicious web page that the victim opens, and based on the description it is inferred that no additional user interaction beyond viewing the page is required.
OpenCVE Enrichment
Debian DLA
Debian DSA