Impact
Out of bounds write in the V8 JavaScript engine can corrupt heap objects when processing a crafted HTML page. This flaw allows a remote attacker to cause memory corruption, potentially leading to arbitrary code execution or denial of service. The weakness is identified as a buffer overread and write, consistent with a covariance in memory management (CWE-787).
Affected Systems
The vulnerability affects Google Chrome across all operating systems where Chrome is available – Windows, macOS, and Linux. Versions of Chrome prior to 146.0.7680.153 are impacted; installing any newer release mitigates the problem.
Risk and Exploitability
The vulnerability carries a high severity CVSS score of 8.8 and has a very low EPSS score (<1%), indicating that widespread exploitation is not expected yet. It is not listed in the CISA KEV catalog. Attackers are able to trigger the exploit by delivering a malicious HTML page to a vulnerable browser, either through the Internet or local file inclusion, making the attack vector remote and web-based. Given the nature of the flaw, successful exploitation can compromise confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment
Debian DSA