Impact
Stack buffer overflow in the V8 JavaScript engine of Google Chrome prior to version 150.0.7871.182 allows a remote attacker to execute arbitrary code inside the browser sandbox. The flaw, a classic stack buffer overflow, can be triggered by a specially crafted HTML page, giving the attacker the ability to run code with the privileges of the browser process.
Affected Systems
The vulnerability affects Google Chrome on all desktop platforms that are running a stable channel build earlier than 150.0.7871.182 on Windows, macOS, or Linux; users of these versions may be exposed if they visit malicious or compromised web pages.
Risk and Exploitability
The EPSS score is below 1 % and the flaw is not listed in CISA’s KEV catalog, which indicates a low probability of widespread exploitation at the time of this analysis. Nonetheless, the CVSS score of 8.8 and the ability to execute arbitrary code in the browser sandbox give this vulnerability a high severity rating. The likely attack vector is a remote attacker hosting a malicious web page that serves a crafted HTML payload; a victim visiting that page could trigger the buffer overflow from the client side.
OpenCVE Enrichment
Debian DLA
Debian DSA