Impact
An out-of-bounds write flaw was engine used by Google Chrome versions before 150.0.7871.46, allowing a remote attacker to execute arbitrary code within the browser’s sandbox when a specially crafted HTML page is rendered. The weakness is categorized as CWE‑787. Although Chromium reports the severity as low, achieving code execution inside a sandbox elevates the risk to confidentiality and integrity, as compromised browser processes might be leveraged system resources.
Affected Systems
All Chrome installations that employ the V8 engine in versions earlier than 150.0.7871.46 on any supported desktop platform are affected. The issue is broadly applicable to every Chrome deployment using that V8 build.
Risk and Exploitability
The CVSS score of high severity, while the EPSS score of less than 1% indicates a very small, yet non‑zero, likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers are likely to exploit the flaw via a web‑based attack chain that feeds a crafted HTML page into the browser, leading to an out‑of‑bounds write that grants code execution inside the sandbox. Until affected versions are updated, the threat remains significant.
OpenCVE Enrichment
Debian DLA
Debian DSA