Impact
A race condition exists in the V8 engine of Google Chrome that allows a maliciously crafted HTML page to manipulate internal timing and state, leading to the execution of arbitrary code within the browser sandbox.
Affected Systems
All users of Google Chrome prior to version 152.0.7977.82 are vulnerable. The issue affects the standard desktop edition of Chrome provided by Google.
Risk and Exploitability
The flaw permits remote exploitation because the attacker only needs the user or another process to render a crafted HTML page. Chromium rates the severity as High with a CVSS score of 7.5 and the attack vector is inferred to be external, relying on a user interacting with malicious web content. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, but the ability to execute code inside the sandbox represents a severe security risk to confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment
Debian DLA
Debian DSA