Impact
A type confusion flaw in Chrome's V8 engine allows a remote attacker to run arbitrary code inside the sandbox when a specially crafted HTML page is opened. The weakness is identified as CWE-843 (Inconsistent Type Confusion). The attack leaks into the browser’s sandbox, potentially compromising confidential data or disrupting system operation. The impact is limited to sandbox boundaries but can still be leveraged for further exploitation.
Affected Systems
Google Chrome desktop versions prior to 153.0.8010.52 are affected. The vulnerability exists in all desktop builds of Chrome based on the affected V8 engine revision.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of less than 1 percent suggests a low probability of mass exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to persuade a user to open a malicious HTML page, so social engineering is a necessary component. Once executed, the code runs with sandbox privileges, providing a foothold for subsequent attacks or data exfiltration.
OpenCVE Enrichment
Debian DLA
Debian DSA