Impact
A type confusion flaw in the V8 JavaScript engine used by Google Chrome enables a remote attacker to execute arbitrary code inside the browser's sandbox by serving a specially crafted HTML page. The flaw is a classic type‑confusion vulnerability (CWE‑843) that allows code to run with the permissions of the sandboxed context, potentially facilitating further privilege escalation if sandbox boundaries can be broken. The chromium security team rates the severity as high.
Affected Systems
The affected product is Google Chrome. All versions prior to 152.0.7977.65 contain the vulnerable V8 code and are at risk. No further sub‑product or version granularity is listed beyond the major Chrome version.
Risk and Exploitability
The exploit requires only that the victim browsers a malicious web page, meaning the attack vector is remote via the web and does not need local code execution or privileged access. The EPSS score is less than 1% and the issue is not listed in the CISA KEV catalog, while the CVSS score of 8.8 indicates high severity and the ability to run arbitrary code indicates a significant risk in environments where the browser is exposed to untrusted content. An attacker who can host the crafted page can trigger execution whenever a user visits it, making this a practical threat for phishing or drive‑by attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA