Description
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Google / Chrome152.0.7977.82 – 152.0.7977.82
- Google / Chrome152.0.7977.82
- Google / v815.3.48
News coverage
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-DayThe Hacker News · 17d ago
Updated 9m ago · 8 sources