Impact
An out‑of‑bounds write vulnerability in the V8 JavaScript engine in Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox through a specially crafted HTML page. The flaw maps to CWE‑787 and, by subverting the memory safety of the V8 engine, can lead to the execution of attacker‑supplied code with the privileges of the sandboxed browser process. If exploited, this could enable further privilege escalation, unauthorized data access, or execution of malicious payloads on the user’s system.
Affected Systems
Affected product is Google Chrome. The issue exists in any Chrome installation prior to version 151.0.7922.109, which was the last release before the security patch was rolled out. Users running the stable channel browser before that build are vulnerable.
Risk and Exploitability
The CVSS assessment classifies this issue as High severity, and it is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must deliver a crafted HTML page, so the likely attack vector is a drive‑by or phishing scenario where the user visits an attacker‑controlled web site or opens a malicious email attachment. Although the EPSS score is not available, the potential impact combined with the high severity makes swift remediation a priority.
OpenCVE Enrichment