Impact
The vulnerability is an uninitialized use in the V8 JavaScript engine in Google Chrome, allowing a remote attacker to execute arbitrary code inside a sandboxed process through a crafted HTML page. The issue is identified as CWE-457, indicating that a variable was used before it was properly initialized. This flaw permits the attacker to compromise sandbox boundaries, potentially gaining the same privileges as the browser process and enabling further escalation.
Affected Systems
Google Chrome browsers are affected, specifically all versions prior to 150.0.7871.115 as noted by the vendor. No additional affected product versions are listed in the available data.
Risk and Exploitability
Chromium reports the severity as High, with a CVSS score of 8.8. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through a malicious web page that the user visits, based on the description. Successful exploitation requires the user to load the crafted page, after which the attacker can run code within the sandbox with the same privileges as the browser process. Given the high severity assessment, the potential impact is significant, although the low EPSS value suggests that exploitation may not be widespread.
OpenCVE Enrichment
Debian DLA
Debian DSA