Impact
Type confusion in the V8 JavaScript engine of Google Chrome allows a remote attacker to execute arbitrary code inside the browser's sandbox by opening a crafted HTML page. The vulnerability was reported as high severity by Chromium.
Affected Systems
All installations of Google Chrome on the stable channel older than version 147.0.7727.55 across Windows, macOS, Linux, and other supported platforms are impacted.
Risk and Exploitability
No CVSS or EPSS metrics are provided. Chromium rated the issue as high severity. The attack vector is remote, requiring the user to visit a malicious web page. Successful exploitation would enable execution of code within the browser's sandbox. There is currently no public exploitation evidence, and it is not listed in the CISA Known Exploited Vulnerabilities catalog.
OpenCVE Enrichment
Debian DSA