Impact
The flaw in the V8 engine of Google Chrome before version 151.0.7922.109 permits a remote attacker to run arbitrary code inside the browser’s sandbox by serving a crafted HTML page. Because the code executes with the privileges of the sandbox, the attacker can manipulate the browser session and potentially access data protected by that sandbox.
Affected Systems
All users of Google Chrome versions earlier than 151.0.7922.109 are affected. The issue was fixed in Chrome 151.0.7922.109, so any build older than that is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of < 1% indicates a very low probability of exploitation, though the flaw can still be triggered by simply loading a malicious web page. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an attacker hosts a malicious page that a user loads, which activates the flaw within the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA