Impact
The vulnerability is an integer overflow in the V8 JavaScript engine, catalogued as CWE‑472, that allows a crafted HTML page to trigger buffer overrun. When this overflow occurs, the attacker can execute arbitrary code inside the browser’s sandbox, potentially enabling the execution of native operating‑system code that bypasses the sandbox. This flaw provides a high‑severity attack surface but does not specify known public exploits.
Affected Systems
All installations of Google Chrome built before version 150.0.7871.46 are affected. The vulnerability exists in every platform where Chrome’s V8 engine is present, covering Windows, macOS, Linux, and Android.
Risk and Exploitability
The CVSS score of 8.8 underscores a serious risk, while the EPSS score of less than 1% indicates that exploitation attempts are currently rare. Based on the description, it is inferred that an attacker must deliver a malicious HTML page that the victim opens in Chrome, a common user action. Once the overflow is triggered, arbitrary code runs within the sandboxed environment, potentially escalating privileges to the host operating system if the sandbox is broken.
OpenCVE Enrichment
Debian DLA
Debian DSA