Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
| Vendor | Product | Versions |
|---|---|---|
| chrome | < 146.0.7680.75, 146.0.7680.178 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cve_cpe | 95% |
| debian | debian linux | cert_advisory | 90% |
| fedora | fedora linux | cert_advisory | 90% |
| chrome | cert_advisory | 90% | |
| igel | igel os | cert_advisory | 90% |
Updated affected versions and patch available to 146.0.7680.178, added new CWE and tags related to zero-day and WebGPU.
Initial creation