Impact
A use‑after‑free flaw in the V8 JavaScript engine allows an attacker to execute arbitrary code inside a Chrome sandbox by loading a specially crafted HTML page. The vulnerability is an instance of CWE‑416 and CWE‑825 and is rated as high severity by Chromium. Successful exploitation would give the attacker the ability to run code with the same privileges as the user running Chrome, potentially compromising the entire system.
Affected Systems
The flaw affects Google Chrome web browsers running any V8 version prior to 151.0.7922.109. This includes all desktop releases of Chrome that have not yet received the patch from the latest stable channel update.
Risk and Exploitability
The attack vector is inferred to be a remote attacker delivering a malicious HTML file to a user’s browser; the exploit does not require elevated privileges on the host. Because the flaw enables code execution beyond the sandbox, the risk is high. The EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog, but the high severity rating and remote nature of the attack keep the overall threat level elevated until the patch is applied. The CVSS score is 8.8.
OpenCVE Enrichment
Debian DLA
Debian DSA