Impact
A type confusion bug in V8, the JavaScript engine used by Google Chrome, allowed a remote attacker to read memory that resides within the browser's sandbox when the attacker serves a specifically crafted HTML page. The vulnerability is a classic type confusion flaw (CWE-843) that could be used to circumvent the constraints imposed by the sandbox and potentially reveal sensitive information. The defect was classified by Chromium as Low severity because the memory read capability is limited to the sandboxed environment and does not directly grant system‑wide access.
Affected Systems
The issue affects all Google Chrome releases prior to version 152.0.7977.65. Users on the stable channel who have not upgraded to this version are at risk. The flaw exists in V8, which is embedded in all Chrome builds for desktop platforms.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact. The EPSS score of < 1% suggests a very low likelihood of exploitation observed in the wild, and the vulnerability is not listed in the CISA KEV catalog, pointing to limited public exploitation activity. The attack can only succeed if the user engages with a malicious or tricked web page, so social engineering is the inferred attack vector. Despite the Low severity rating from Chromium, any exploitation would still expose sandboxed data to the attacker.
OpenCVE Enrichment
Debian DLA
Debian DSA