Impact
A use‑after‑free flaw in the V8 JavaScript engine used by Google Chrome allows an attacker to construct a malicious HTML page that, when rendered by the browser, triggers the execution of arbitrary code inside Chrome’s sandbox. The vulnerability, classified as CWE‑416, enables remote code execution. Based on the description, it is inferred that loading the crafted page may trigger the exploit, but the CVE data does not explicitly state whether additional user interaction is needed.
Affected Systems
All installations of Google Chrome that use a V8 engine before the release 152.0.7977.65 are affected. The CVE data does not specify an operating‑system limitation, so the flaw is present on any platform running these build versions. Updating to Chrome 152.0.7977.65 or later eliminates the vulnerability.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is described as executable via a crafted HTML page, and it is inferred that loading that page may be sufficient to trigger the exploit, but the CVE data does not explicitly note whether additional user interaction is required. This uncertainty makes assessment of exploitability more complex for sites serving potentially malicious content to affected browsers.
OpenCVE Enrichment
Debian DLA
Debian DSA