Impact
A flaw in the V8 JavaScript engine of Google Chrome permits a remote attacker to execute arbitrary code inside the browser sandbox by loading a specially crafted HTML page. The weakness is an out‑of‑bounds write designated as CWE-787. Although the code runs only within the sandbox, it can manipulate browser state or interact with privileged processes delegated through the browser’s sandboxing mechanisms, potentially facilitating further compromise if a sandbox escape is achieved.
Affected Systems
All releases of Google Chrome prior to version 153.0.8010.36 on any supported operating system are affected. Upgrading to 153.0.8010.36 or later applies the patch that removes the out‑of‑bounds write, thereby preventing this vulnerability from being triggered by malicious content.
Risk and Exploitability
The attacker’s vector is inferred to be remote via a malicious HTML document, as the vulnerability is triggered by crafted web content. The CVSS score of 8.8 indicates high severity. The EPSS score is 3 %, and the vulnerability’s listing in the CISA KEV catalog shows that it is actively exploited in the wild. Because the code executes only within the sandbox, the immediate impact is confined to sandboxed code execution, yet the overall risk remains high for systems that may load untrusted content, and a successful sandbox escape could lead to full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA