Impact
The vulnerability is a buffer overflow in Google Chrome's V8 JavaScript engine that allows a remote attacker to execute arbitrary code within the browser’s sandbox. The description explicitly states that code execution is possible inside the sandbox, and based on that detail it is inferred that the overflow could also permit code injection (CWE-94). This overflows and the reported result is arbitrary code execution.
Affected Systems
All users of Google Chrome on desktop platforms whose installations are older than version 150.0.7871.46, any stable channel build that has not applied the June 2026 update.
Risk and Exploitability
The CVSS score of 8.8: a remote attacker serving a malicious HTML page that, when rendered by the victim’s browser, triggers code into the sandbox, resulting in full remote code execution within the user’s browser context. The EPSS score of < 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA