Impact
The vulnerability is an inappropriate implementation in the V8 JavaScript engine of Google Chrome versions prior to 146.0.7680.153. It permits a heap overflow when an attacker delivers a specially crafted HTML page, potentially leading to arbitrary code execution. The weakness is a classic out‑of‑bounds write identified as CWE‑787.
Affected Systems
All installations of Google Chrome running before version 146.0.7680.153 on Windows, macOS, or Linux are affected. The issue is not limited to a specific feature or user role; any user visiting a malicious site with the buggy browser is at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while an EPSS score of less than 1% suggests low likelihood of immediate exploitation. It is not listed in the CISA KEV catalog. Attackers can remotely exploit the flaw by delivering malicious content to the victim’s browser; no local privileges are required. Successful exploitation could allow execution of arbitrary code within the browser process, compromising the victim’s system confidentiality, integrity, and availability.
OpenCVE Enrichment
Debian DSA