Impact
This‑free flaw (CWE‑416) in the V8 JavaScript engine used by Google Chrome. A crafted HTML page can trigger the defect, allowing a remote attacker to execute arbitrary code within the browser’s sandbox.
Affected Systems
Google Chrome versions earlier than 150.0.7871.46 are exposed regardless of the underlying operating system.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of <1% suggests a low current exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack requires a user to visit a malicious web page that contains the crafted content, making phishing or drive‑by‑download vectors the most likely paths.
OpenCVE Enrichment
Debian DLA
Debian DSA