Impact
The flaw is an incorrect calculation inside the V8 JavaScript engine in Google Chrome versions prior to 151.0.7922.169. A crafted HTML page sent to the victim can trigger the calculation bug and cause the sandbox to be bypassed, allowing the attacker to execute arbitrary code with the privileges of the browser. This is a direct remote code execution vulnerability classified as CWE-682.
Affected Systems
Google Chrome browsers on all platforms using the V8 engine and running any stable channel version older than 151.0.7922.169 are affected. The issue is limited to Chrome’s normal operation when processing HTML content; no additional components are mentioned.
Risk and Exploitability
The vulnerability is high severity and, although no EPSS score is available, the lack of a KEV listing does not diminish the risk. The likely attack vector is a web page that a user visits or that loads in a web‑based application. Exploitation requires no privileged interaction beyond normal browsing; any user who opens a maliciously crafted page could be compromised.
OpenCVE Enrichment