Impact
A race condition in the V8 JavaScript engine of Google Chrome allows a remote attacker to execute arbitrary code within the browser’s sandbox when a victim opens a specially crafted HTML page. The flaw provides a path to break out of the sandbox and run code with the privileges of the local user, thereby compromising confidentiality, integrity, and availability of the affected system. The weakness is categorized as a race condition, CWE-362.
Affected Systems
Google Chrome browsers rendering the vulnerable V8 engine before version 152.0.7977.65 are affected. All users running these releases on any platform that includes this browser kernel are susceptible to the flaw.
Risk and Exploitability
The CVSS score is 7.5, and the EPSS score is < 1%; the vulnerability is not currently in the CISA KEV catalog, suggesting no widespread, publicly documented exploitation yet. The likely attack vector is a malicious webpage that a user visits or receives via a link. An attacker can craft the HTML to trigger the race condition, and the lack of complexity barriers indicates that exploitation would not require special prerequisites beyond delivering the page to the victim’s browser.
OpenCVE Enrichment
Debian DLA
Debian DSA