Impact
An incorrect memory handling routine in V8 allows a crafted HTML page to corrupt Chrome’s heap. This heap-based buffer overrun (CWE-122) is triggered when a user interacts with specific UI gestures on a malicious page. The description does not confirm that the corruption can be leveraged for arbitrary code execution; the primary effect appears to be instability or data corruption within the browser process.
Affected Systems
All desktop installations of Google Chrome running a V8 engine older than 150.0.7871.46, regardless of operating system, are affected.
Risk and Exploitability
The CVSS score of 8.8 signals high severity, while an EPSS score of less than 1% indicates a very low probability of exploitation, implying that a user must visit a malicious page and perform specific UI gestures for the vulnerability to be triggered. The potential for arbitrary code execution is not confirmed.
OpenCVE Enrichment
Debian DLA
Debian DSA