Impact
A use‑after‑free flaw in the V8 JavaScript engine of Google Chrome allows a remote attacker to run arbitrary code inside the browser’s sandbox when a specially crafted HTML page is loaded. The vulnerability is classified as high severity by Chromium security.
Affected Systems
Google Chrome browsers with a version number earlier than 153.0.8010.47 are affected. This includes all stable channel releases prior to that version. Any installation that has not been updated to 153.0.8010.47 or later runs the risk.
Risk and Exploitability
The CVSS score of 8.8 reflects a high impact potential. The EPSS score of less than 1 % indicates that the likelihood of exploitation is low, although a determined attacker could still prepare an exploit. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a remote web page that the victim loads, which then triggers the use‑after‑free within V8 to execute code inside the sandbox.
OpenCVE Enrichment