Impact
An out-of-bounds read and write flaw in the V8 JavaScript engine of Google Chrome existed before version 148.0.7778.96. This corresponds to the CWE-125 and CWE-787 weaknesses involving unvalidated bounds checking and out-of-bounds writes. A remotely crafted HTML page can exploit this flaw to read and overwrite memory, enabling an attacker to execute arbitrary code inside the sandbox that Chrome uses to isolate web content. The vulnerability is classified as high severity by Chromium security.
Affected Systems
All desktop installations of Google Chrome that are older than 148.0.7778.96 on the stable channel are affected. The flaw is present in every build shipped before that release, regardless of operating system, because it resides in the core V8 runtime.
Risk and Exploitability
The vulnerability can be triggered simply by loading a malicious web page in the browser; no additional privileges are required. Though exploitation is confined to the sandbox, it allows arbitrary code execution inside that environment, making it a high-impact issue. The EPSS score is not available and the vulnerability is not listed in CISA KEV. The CVSS score is 8.8.
OpenCVE Enrichment
Debian DSA