Impact
The vulnerability arises from a type‑confusion flaw in the V8 JavaScript engine that powers Chrome. In Chrome versions prior to 144.0.7559.132 a malformed object could be misinterpreted, causing heap corruption that may allow an attacker to execute arbitrary code or crash the browser, thereby jeopardizing confidentiality, integrity and availability of the user’s environment.
Affected Systems
All installations of Google Chrome 144.0.7559.131 and earlier on Windows, macOS and Linux are susceptible. The flaw resides solely in the browser component and is independent of the underlying operating system, so any user running those versions is at risk until an update is applied.
Risk and Exploitability
The CVSS score of 8.8 reflects a high‑severity impact, while an EPSS score of less than 1% indicates a very low but non‑zero likelihood of current exploitation and the vulnerability is not listed in CISA’s KEV catalog. Exploitation would require delivery of a crafted HTML page to the victim, a common web‑based attack vector. The combination of high impact and low exploitation probability suggests client‑side mitigation through timely updates is critical.
OpenCVE Enrichment
Debian DSA