Impact
An uninitialized‑use flaw within the V8 JavaScript engine allows a remote attacker to execute arbitrary code in the context of the browser’s sandboxed process when a crafted HTML page is rendered. The vulnerability carries a CVSS score of 9.6, signifying a severe risk to both confidentiality and integrity of data handled by the browser.
Affected Systems
Google Chrome browsers with a version earlier than 150.0.7871.46 are affected. This assessment applies to any operating system on which Chrome runs; the simplifying inference is made because the CVE description does not specify a platform limitation.
Risk and Exploitability
The high CVSS score indicates a serious threat, while the EPSS score of less than 1% suggests that exploitation attempts are currently rare. An attacker can trigger the flaw by delivering a specially crafted HTML page that the browser loads, leading to code execution within the sandbox. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been observed to date.
OpenCVE Enrichment
Debian DLA
Debian DSA