Impact
Chrome’s V8 JavaScript engine contains an out‑of‑bounds read and write bug that can be triggered from a specially crafted HTML page. The flaw permits a remote attacker to read or corrupt memory beyond intended bounds and thereby execute arbitrary code inside the browser’s sandbox. This could allow an attacker to execute arbitrary code within the sandbox.
Affected Systems
All users running Google Chrome versions earlier than 150.0.7871.128 are vulnerable. The issue has been fixed in Chrome 150.0.7871.128 and later releases.
Risk and Exploitability
The CVSS score of 8.8 reflects a high impact due to remote code execution. The EPSS value is below 1 %, indicating a low likelihood of attack at this time, and the vulnerability is not catalogued in CISA’s KEV. Attackers would need to supply a malicious HTML page that is rendered by the victim’s browser, making the vulnerability exploitable over the network through a normal browsing channel. The lack of a publicly known exploit, combined with the low EPSS, suggests the risk is moderated but the damage potential remains high.
OpenCVE Enrichment
Debian DLA
Debian DSA