Impact
Inappropriate implementation in the V8 JavaScript engine of Google Chrome versions prior to 148.0.7778.216 permits a remote attacker to execute arbitrary code within the browser’s sandbox by serving a crafted HTML page. The flaw allows code to run with the privileges of the sandboxed process, potentially enabling a pivot to higher‑level resources if the sandbox is breached.
Affected Systems
All users running Google Chrome releases older than 148.0.7778.216 are affected; no operating‑system restriction is indicated in the vendor’s description.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is reported as less than 1 %, signifying a low but nonzero likelihood of exploitation when this analysis was performed. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, requiring an attacker to deliver a malicious HTML payload through a web page that the user is directed to.
OpenCVE Enrichment