Impact
Buffer overflow in the V8 JavaScript engine of Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox when a malicious HTML page is loaded. This flaw corresponds to CWE‑121.
Affected Systems
Google Chrome desktop clients running any version of Chrome before 152.0.7977.65 are affected.
Risk and Exploitability
The vulnerability can be exploited remotely via a crafted web page and carries a CVSS score of 8.8, categorizing it as a high severity flaw. The EPSS score is less than 1%, indicating a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. An attacker could achieve code execution within the sandbox, potentially leaking data or moving to higher privilege levels if further exploits are chained.
OpenCVE Enrichment
Debian DLA
Debian DSA