Impact
An inappropriate implementation in the V8 JavaScript engine of Google Chrome allowed a remote attacker to execute arbitrary code inside a sandbox through a crafted HTML page, resulting in full loss of confidentiality, integrity, and availability of the user’s system. The weakness, identified as CWE‑843, leads to remote code execution.
Affected Systems
The vulnerability affects Google Chrome browsers version 146.0.7680.153 and earlier. All operating systems that run Chrome – Windows, macOS, and Linux – are impacted as the defect exists in the core JavaScript engine shared across platforms.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity, while the EPSS score of less than 1% indicates limited exploit probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to host a malicious web page that the victim visits; the attack vector is a web exploits scenario, allowing remote code execution within the browser sandbox.
OpenCVE Enrichment
Debian DSA