Impact
A use‑after‑free flaw was discovered in the V8 JavaScript engine embedded in Google Chrome, allowing a remote attacker to trigger arbitrary code execution inside the browser sandbox by delivering a specially crafted HTML page. The vulnerability arises when the engine fails to properly release memory before it is accessed again, resulting in a vulnerability classified as CWE‑416. Successful exploitation permits the attacker to run arbitrary code, potentially compromising the confidentiality, integrity, or availability of the affected system.
Affected Systems
Google Chrome browsers prior to version 152.0.7977.65 are impacted. The flaw affects all builds of the stable channel that have not yet received the update listed in the Chrome release notes.
Risk and Exploitability
Although classified with a CVSS score of 8.8, the vulnerability allows remote code execution that can be triggered by an attacker through a web page rendered in the browser. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be a remote, client‑side exploitation that requires the victim to encounter a maliciously crafted web page, making the risk high in environments that expose users to untrusted content.
OpenCVE Enrichment
Debian DLA
Debian DSA