Описание
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
A flaw was found in V8, the open-source JavaScript engine used in Google Chrome. This type confusion vulnerability allows a remote attacker to execute arbitrary code within the browser's security sandbox. Exploitation occurs when a user visits a specially crafted HTML page, leading to potential compromise of the affected system.
Отчет
This vulnerability is rated as Important. A type confusion flaw in the V8 JavaScript engine can lead to remote code execution when processing a specially crafted HTML page. Exploitation requires user interaction, as an attacker must entice a user to visit a malicious website. This primarily impacts desktop environments and applications that render untrusted web content, such as Chromium and applications embedding QtWebEngine.
Меры по смягчению последствий
To mitigate this vulnerability, users should avoid opening untrusted web content or visiting untrusted websites. For systems where web browsing functionality is not required, consider removing packages that provide web rendering capabilities, such as chromium or qt5-qtwebengine/qt6-qtwebengine. Note that removing these packages may impact the functionality of other desktop applications or the desktop environment itself.
Дополнительная информация
Статус:
8.8 High
CVSS3
Связанные уязвимости
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed ...
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
8.8 High
CVSS3