Impact
An out‑of‑bounds write was discovered in the V8 JavaScript engine used by Google Chrome. The flaw allows a remote attacker to execute arbitrary code inside the browser’s sandbox by serving a specially crafted HTML page, and was rated as a high‑severity issue by Chromium security. The vulnerability focuses on improper bounds checking of memory during script execution, leading to uncontrolled write operations.
Affected Systems
The affected product is Google Chrome before version 148.0.7778.216. All users running any older stable channel build faced potential exploitation when visiting malicious web pages containing the crafted payload.
Risk and Exploitability
The CVSS score of 8.8 reflects a high‑severity flaw, yet the vulnerability is still not listed in CISA KEV and EPSS data is unavailable. Exploitation requires a user to open or trigger the crafted HTML content in a Chrome browser, making the attack vector client‑side. Successful exploitation would compromise the browser sandbox and could lead to arbitrary code execution on the host system. Given the lack of active public exploits, the realistic threat remains moderate to high until an exploit is found or the pending automatic update is deployed.
OpenCVE Enrichment