Impact
The vulnerability is a buffer overflow that occurs within the font rendering component of Google Chrome. A remote attacker, after compromising the renderer process, can trigger the overflow by delivering a specially crafted HTML page, potentially allowing execution of arbitrary code outside the sandbox. The primary impact is remote code execution with the ability to escape sandbox protections. The likely attack vector is inferred to be through a malicious web page or data that the user opens, which would be parsed by the compromised renderer.
Affected Systems
Google Chrome versions earlier than 155.0.8059.39 are affected. These include all builds of the stable channel prior to the mentioned version.
Risk and Exploitability
The CVSS score is not explicitly provided in the data, and the EPSS score is unavailable, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires prior compromise of the renderer process, the attack conditions are relatively high. However, once the renderer is compromised, the attacker can achieve remote code execution beyond Chrome’s sandbox. The vendor’s public release notes indicate that the issue is fixed in 155.0.8059.39; therefore, updating mitigates the risk.
OpenCVE Enrichment