Impact
An integer overflow condition in Chrome’s V8 JavaScript engine permits a remote attacker to corrupt the heap when rendering a specially crafted HTML page. This flaw carries a high severity score of 8.8 and can potentially lead to remote code execution on the affected system.
Affected Systems
The vulnerability affects all instances of Google Chrome before version 145.0.7632.109. Any user who visits a malicious web page with that Chrome build is at risk.
Risk and Exploitability
The exploit score is low (EPSS < 1 %) and the flaw is not listed in the CISA KEV catalog, but the high CVSS score and the possibility of heap corruption make it a serious threat. The likely attack vector is a remote adversary sending a malicious HTML page that the victim’s browser processes, exploiting the integer overflow to overwrite memory.
OpenCVE Enrichment
Debian DSA