Impact
This vulnerability is a type confusion flaw in the V8 JavaScript engine used by Google Chrome before version 147.0.7727.55. A maliciously crafted HTML page can trigger the bug and allow an attacker to execute arbitrary code within the browser's sandbox. The flaw is classified as CWE‑843 and results in a serious loss of confidentiality, integrity, or availability of the victim system.
Affected Systems
The affected product is Google Chrome running on Windows, macOS, or Linux. Versions prior to 147.0.7727.55 are vulnerable. All operating systems that ship with Chrome are potentially impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The flaw is not listed in the CISA KEV catalog, but a crafted webpage that a user opens could deliver the exploit. Because the attack requires a user to visit a malicious page, the risk is moderate, and remediation should be prioritized.
OpenCVE Enrichment
Debian DSA