Описание
Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
A flaw was found in V8, the JavaScript engine used in Google Chrome. This integer overflow vulnerability allows a remote attacker to execute arbitrary code within the browser's security sandbox—a protective environment that limits what a program can do. This can occur when a user visits a specially crafted HTML page, potentially leading to unauthorized operations within the sandboxed environment.
Отчет
This is an Important vulnerability in the V8 JavaScript engine, utilized by Chromium-based browsers. An integer overflow allows a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. The requirement for user interaction to trigger the flaw contributes to its Important severity, as direct network exploitation without user action is not possible.
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowe ...
Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
EPSS
8.8 High
CVSS3