Impact
The flaw is a race condition in the font handling subsystem of Google Chrome versions earlier than 155.0.8059.39. It permits a crafted HTML page to trigger a timing discrepancy during font processing, which can break out of the browser sandbox and allow execution of arbitrary code on the host system. The weakness is catalogued as CWE-362, reflecting the concurrent manipulation of shared data. The impact is therefore denial of system integrity at a system-wide level, as the attacker could gain full privileges depending on the operating system's sandbox boundaries.
Affected Systems
The affected product is Google Chrome, across all desktop platforms that ship with any version prior to 155.0.8059.39. The exact versions are unlisted in the vendor data, but the reference release notes indicate the fix is present in the 155.0.8059.40 update. Users running older Windows, macOS, or Linux builds of Chrome are vulnerable.
Risk and Exploitability
The CVSS score of 8.3 classifies this as high severity. The EPSS score is not available, but the absence of a KEV listing does not mitigate the risk; the vulnerability remains medium to high likelihood of exploitation in the wild, especially for malicious websites or phishing pages. The likely attack vector is a remote adversary serving a malicious HTML payload to a victim’s browser, exploiting the font race condition to escape the sandbox.
OpenCVE Enrichment