Impact
A type confusion bug in the V8 JavaScript engine of Google Chrome allows a remote attacker to trigger arbitrary code execution inside the browser’s sandbox when a user opens a specially crafted HTML page. The vulnerability is leveraged through social engineering, requiring no additional privileges. Once executed, code runs with the sandboxed renderer process privileges, potentially accessing or altering data the browser has downloaded or stored.
Affected Systems
The flaw exists in Google Chrome builds earlier than version 152.0.7977.65 on desktop platforms; any user running those builds is affected.
Risk and Exploitability
The attack requires a victim to visit a malicious page, a common social‑engineering scenario. The EPSS score is less than 1%, and the issue is not listed in the CISA KEV catalog, yet the CVSS score of 8.8 indicates a high severity flaw. The risk is actionable because the flaw can be triggered remotely without local code execution privileges, and effective mitigation is possible by upgrading the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA