Impact
The vulnerability is a type confusion bug in the V8 JavaScript engine used by Google Chrome. It allows a remote attacker to read memory inside the sandbox through a specially crafted HTML page. This could expose the contents of the sandbox and potentially enable further exploitation of privileges within the browser process.
Affected Systems
Google Chrome on all platforms, for all releases earlier than version 153.0.8010.36.
Risk and Exploitability
Chromium classifies this flaw as high severity with a CVSS score of 4.3. The EPSS score is < 1%, and it is not listed in the CISA KEV catalog. The exploit requires delivery of a malicious web page that triggers V8's type confusion, meaning an attacker could target users by hosting a malicious site or injecting the payload into compromised content. As the vulnerability permits reading of sandbox memory, it offers an opportunity for attackers to gather sensitive data and potentially pivot to additional attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA