Impact
A use‑after‑free flaw in the V8 JavaScript engine within Google Chrome, identified as CWE‑416, allows an attacker to trigger arbitrary code execution inside the browser sandbox through a specially crafted HTML page. The vulnerability is remote; a malicious website can exploit it to run code in the sandboxed environment, potentially compromising user data or surreptitiously initiating further actions without the user’s permission.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 are affected. The flaw resides in the V8 engine that ships with the stable channel of Chrome. Users on any platform running those versions are vulnerable.
Risk and Exploitability
The vulnerability carries a high severity rating according to Chromium’s assessment. No EPSS score is available, and the issue is not listed in CISA’s KEV catalog, but the nature of the flaw—remote exploitation via a web page—and the prevalence of Chrome browsing make it a significant risk. An attacker would need to lure a user to a malicious HTML page; once the page loads, the use‑after‑free can be triggered to run code within the sandbox, giving the attacker high‑privilege access within the browser context.
OpenCVE Enrichment