Impact
Race condition in the V8 engine of Google Chrome allows a remote attacker to run arbitrary code inside the sandbox by serving a crafted HTML page. The flaw is a classic data‑race condition that can be triggered when the browser parses concurrent scripting contexts. Because the sandbox is designed to isolate web content, an exploit would allow the attacker to escape this isolation and gain code execution capabilities on the host system.
Affected Systems
Google Chrome browsers prior to version 154.0.8037.57 are vulnerable. The issue exists across all desktop releases that use the V8 JavaScript engine before the mentioned update.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is not available, so no current estimate of exploitation probability can be provided, but the vulnerability is listed as high in Chromium’s own severity taxonomy. The flaw is not yet recorded in CISA’s KEV catalog, so there are no known large‑scale exploits yet. Exploitation would likely occur through a malicious web page or infected content that a user opens in Chrome.
OpenCVE Enrichment
Debian DSA