Impact
An uninitialized‑use flaw in the V8 JavaScript engine within Google Chrome enables an attacker to execute arbitrary code while the browser is running. The vulnerability is classified as CWE‑457 and carries a CVSS score of 9.6, indicating a severe threat to both confidentiality and integrity. Because the flaw occurs inside the sandboxed browser process, the attacker can potentially inject or run malicious code without requiring elevated system privileges.
Affected Systems
All instances of Google Chrome running a version earlier than 150.0.7871.46 are affected. The flaw applies to any operating system that hosts Chrome, as the description does not specify a platform limitation. No version or patch level information beyond the stated cutoff is provided.
Risk and Exploitability
The high CVSS score emphasizes the seriousness of the vulnerability, while the EPSS score of less than 1 % suggests that exploitation attempts are currently rare. The likely attack vector is a crafted HTML page that, when rendered by the browser, triggers the uninitialized use path and leads to code execution within the sandbox. The flaw is not listed in the CISA KEV catalog, indicating that no widespread exploitation has been observed to date.
OpenCVE Enrichment
Debian DLA
Debian DSA