Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
The flaw consists of the use of uninitialized memory (CWE-457, Uninitialized Use) in the V8 engine responsible for executing JavaScript code. An attacker can prepare a specially crafted HTML page whose processing by the V8 engine leads to reading or performing operations on uninitialized data in memory. As a result, arbitrary code execution is possible within the browser sandbox. User interaction is limited to visiting the attacker-controlled website.
An attacker can execute arbitrary code (RCE) in the context of the browser's rendering process, limited by the sandbox. In combination with a potential exploit enabling sandbox escape, the impact could include full system compromise.
Google Chrome must be updated to version 150.0.7871.46 or later. The update is available through the browser's automatic update mechanism or according to information published on the Chrome Releases blog.
Google Chrome versions prior to 150.0.7871.46
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HGoogle Chrome
APPGoogle< 150.0.7871.46
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox