Impact
Google Chrome versions before 154.0.8037.97 contain a buffer overflow in the WebRTC component. An attacker can supply a specially crafted HTML page that triggers the overflow, enabling them to run arbitrary code inside Chrome's sandbox. The vulnerability is a classic buffer overflow (CWE‑122) and, if successfully exploited, could lead to full system compromise with the privileges granted to the user’s sandbox.
Affected Systems
All users of Google Chrome on any platform who are running Chrome prior to version 154.0.8037.97 are affected. The issue was identified in the WebRTC module and applies to the stable channel of Chrome. Users of newer releases are not impacted.
Risk and Exploitability
The flaw is a remote, cross‑site vulnerability that requires nothing more than the user loading a malicious web page. The severity is rated high, but no exploit probability (EPSS) data is available, and the vulnerability is not listed in CISA’s KEV catalog. Because the vulnerability can be triggered via standard browser activity, the likelihood of exploitation is non‑negligible, especially in environments lacking robust web filtering.
OpenCVE Enrichment