Out of bounds read and write vulnerability affecting V8 in Google Chrome versions prior to 149.0.7827.103, reported on April 27 by a security researcher, allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
| Vendor | Product | Versions |
|---|---|---|
| chrome | 149.0.7827.103, 149.0.7827.102 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| chrome | cert_advisory | 90% |
Updated description with more technical detail, added CWE-125, and included new tags related to zero-day and high-severity.
Updated affected versions to include 149.0.7827.102, changed severity to CRITICAL, and added new tags related to security and exploit.
Updated description with more technical detail, marked as actively exploited, and noted that a patch is available.
Initial creation