Impact
The flaw is an integer overflow in the V8 JavaScript engine of Google Chrome before version 150.0.7871.46. A crafted HTML page that triggers the overflow lets a remote attacker execute arbitrary code inside the browser’s sandbox. The vulnerability is identified as CWE‑472.
Affected Systems
All installations of Google Chrome prior to version 150.0.7871.46 are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1% suggests exploitation is currently rare. It is not listed in CISA’s KEV catalog. An attacker must deliver a malicious HTML page that the victim opens in Chrome. When the overflow is triggered, arbitrary code runs within the sandbox, potentially compromising data and browser integrity.
OpenCVE Enrichment
Debian DLA
Debian DSA