Description
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Google / Chrome153.0.8010.36 – 153.0.8010.36
- Google / Chrome153.0.8010.36
News coverage
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside SandboxThe Hacker News · 12d ago
Updated 9m ago · 8 sources