Impact
The flaw is an incorrect calculation inside the V8 JavaScript engine in Google Chrome versions prior to 151.0.7922.169. A crafted HTML page sent to the victim can trigger the calculation bug and cause the sandbox to be bypassed, allowing the attacker to execute arbitrary code with the privileges of the browser. This is a direct remote code execution vulnerability, involving an integer overflow (CWE-190) and an incorrect calculation (CWE-682).
Affected Systems
Google Chrome browsers on all platforms using the V8 engine and running any stable channel version older than 151.0.7922.169 are affected. The issue is limited to Chrome’s normal operation when processing HTML content; no additional components are mentioned.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is below 1%, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is a crafted HTML page delivered via a browser, and exploitation requires no privileged interaction beyond normal browsing; any user who opens such a page could be compromised.
OpenCVE Enrichment
Debian DLA
Debian DSA