Impact
A type confusion flaw in the V8 JavaScript engine of Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox. The vulnerability is classified as CWE‑843 and can be triggered by loading a specially crafted HTML page.
Affected Systems
Google Chrome browsers running any revision before 150.0.7871.46 are vulnerable, covering all stable channel releases below that revision. The issue was fixed in Chrome 150.0.7871.46 and later.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while an EPSS score of <1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The vulnerability can be triggered by loading a specially crafted HTML page, allowing code to execute within the browser sandbox with the privileges granted to the user’s browser process.
OpenCVE Enrichment
Debian DLA
Debian DSA