Impact
A flaw in the V8 JavaScript engine in Google Chrome before version 151.0.7922.109 allows a remote attacker to write and execute arbitrary code inside the browser’s sandbox by serving a specially crafted HTML page. The vulnerability is a high‑severity flaw in Chromium’s security system. Exploiting this defect permits an attacker to run code the browser considers trusted, thereby circumventing the sandbox that normally isolates web content from the underlying operating system.
Affected Systems
All installations of Google Chrome running any operating system that are earlier than version 151.0.7922.109 are affected. The vulnerability is independent of the platform because it resides in the V8 engine used by every Chrome browser process. No specific OS or product variant is excluded from the impact.
Risk and Exploitability
An attacker can trigger the compromise simply by driving a user to load a malicious web page that contains the crafted payload. The flaw grants remote code execution within the sandboxed Chrome process; while the sandbox limits lateral movement, the compromised process can still affect data or privacy within its own domain. The CVSS score of 8.8 reflects a high severity, the EPSS score of 0.00442 (approximately 0.44%) indicates a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. The documented attack vector is a malicious HTML page opened in the browser, implying an easy, web‑based exploitation pathway.
OpenCVE Enrichment
Debian DLA
Debian DSA