Impact
The vulnerability is an uninitialized resource in the V8 JavaScript engine used by Google Chrome. A crafted HTML page can cause the engine to execute arbitrary code within the Chromium sandbox, effectively leading to remote code execution.
Affected Systems
The flaw exists in all Google Chrome desktop releases before 152.0.7977.75. Users of these legacy versions—whether on Windows, macOS or Linux—are susceptible as the vulnerability is triggered by loading a malicious or maliciously crafted web page.
Risk and Exploitability
Chromium labels the issue as High severity, and the EPSS score is currently unavailable, but the flaw is not present in the CISA KEV list. The attack vector is remote, requiring only a web page to be opened in the vulnerable browser. No authentication or elevated privileges are needed beyond the normal browser session. The absence of an EPSS value makes it difficult to gauge real-world exploitation frequency, yet the high severity indicates a significant risk should attackers create malicious content.
OpenCVE Enrichment