Impact
An out‑of‑bounds write flaw exists in the V8 JavaScript engine of Google Chrome versions earlier than 154.0.8037.57. An attacker can trigger the flaw by delivering a specially crafted HTML page, allowing execution of arbitrary code within the browser sandbox. The vulnerability corresponds to CWE‑787, a typical memory corruption issue that can be leveraged for remote code execution.
Affected Systems
Google Chrome browsers in any stable channel, inferred from the Chrome release schedule, with a version number lower than 154.0.8037.57 are affected; the conclusion that only stable channel builds are affected is inferred, as the input does not explicitly state this. The issue is documented for all Chrome releases before that specific build.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, classified as high severity. No EPSS data is available, so the current exploitation probability cannot be quantified, but the vulnerability has not yet appeared in the CISA Known Exploited Vulnerabilities catalog. Attackers would need to persuade a user to visit a malicious webpage containing the exploit payload; once activated, the code runs with browser privileges, potentially bypassing sandbox restrictions.
OpenCVE Enrichment
Debian DSA