Impact
A buffer under‑read (CWE‑125) in V8 can be triggered by a crafted HTML page, giving an attacker the ability to execute arbitrary code within Chrome’s sandbox. The flaw allows reading beyond a valid buffer boundary and can be leveraged to run code with the privileges of the user’s browser process, effectively breaking the sandbox isolation that ordinarily protects the rest of the system.
Affected Systems
Google Chrome is affected. Any Chrome installation running a version earlier than 151.0.7922.72 is vulnerable. Users on Windows, macOS, or Linux using the stable channel are subject to this flaw until they update to a patched release.
Risk and Exploitability
The exploit is remote, initiated through a maliciously crafted web page, so network exposure to the Internet presents an attack surface. The EPSS score is < 1% and the vulnerability is not catalogued in CISA’s KEV listing, suggesting that it may not yet have public exploits. The CVSS score of 8.8 indicates a high severity, implying that the flaw can be abused but may require a well‑crafted delivery mechanism. The primary attacker would need to lure a user to a site that hosts the malicious payload, making user education and cautious browsing part of the mitigation strategy.
OpenCVE Enrichment