Impact
An insecure implementation in the V8 JavaScript engine of Google Chrome enables a remote attacker to run arbitrary code within the browser sandbox. By serving a specially crafted HTML page, the attacker can bypass sandbox restrictions and execute code with the privileges of the user. The vulnerability is marked high severity with a CVSS score of 8.8, indicating significant potential for damage.
Affected Systems
This flaw affects Google Chrome versions earlier than 147.0.7727.55 on all supported operating systems, including macOS, Linux, and Windows. The CPE data confirms that any Chrome installation running a vulnerable version is impacted, regardless of the underlying OS.
Risk and Exploitability
The low EPSS score of under 1% suggests that exploitation is not yet widespread, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the high CVSS score and remote execution capability make it a serious threat. An attacker could gain full code execution inside the user's session by merely loading a malicious webpage, making patching the highest priority.
OpenCVE Enrichment
Debian DSA