Impact
A type confusion flaw was found in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox. The vulnerability arises when the engine misidentifies an object type during script execution, enabling maliciously crafted HTML pages to control privilege escalation within the sandbox. The effect is the ability to run code with the same privileges as the sandboxed browser process.
Affected Systems
Google Chrome version 153.0.8010.36 or earlier are impacted. Any system that installs an affected Chrome version without updating to 153.0.8010.36 or later is vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8 and can be triggered remotely through a crafted web page, meaning an attacker only needs the user to visit a malicious site. The EPSS score is < 1%, indicating a low but non‑zero exploitation probability, and the flaw is not listed in CISA’s KEV catalog, but the high severity and the ease of exploitation through standard browsing paths suggest strong potential for real-world attacks. Immediate patching is required to mitigate this risk.
OpenCVE Enrichment
Debian DLA
Debian DSA