Impact
Type confusion in the V8 JavaScript engine allows a remote attacker to execute arbitrary code inside the Chrome sandbox through a specially crafted HTML page. This flaw means that malicious scripts can run with the privileges granted to the sandboxed process, potentially compromising the functionality of the browser or affecting other tabs that share the same sandbox context. The impact is limited to sandbox boundaries; escaping the sandbox is not demonstrated in the description, but the ability to run code within the sandbox is a significant vector for further attacks.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected. The vulnerability exists in the Chromium V8 engine used across desktop Chrome installations.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high severity. The EPSS score is < 1%, suggesting a very low but non-zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed public exploitation at this time. The likely attack vector is through a web page that a user visits; the crafted content would trigger the type confusion during script parsing or execution. As the exploit requires privileged code within the sandbox, it can be mitigated by applying the vendor patch that updates the V8 engine to the fixed version.
OpenCVE Enrichment
Debian DLA
Debian DSA