Impact
A stack buffer overflow in the GPU component of Google Chrome allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. The overflow is triggered by a crafted HTML page, providing the attacker the potential to escape the renderer sandbox and execute code in a higher privilege context within the browser process. The weakness is a classic stack-based buffer overflow, classified as CWE‑121.
Affected Systems
Google Chrome desktop builds, prior to version 149.0.7827.53, on all platforms that include the GPU process. Users who are running any older stable channel release are affected and should upgrade to the latest available build.
Risk and Exploitability
The vulnerability is rated as Critical by the Chromium security team. No EPSS score is available, and it is not listed in CISA KEV, but the exploit would require first delivering a malicious HTML page that loads in a compromised renderer. The attack vector is likely a user visiting or interacting with a malicious website, permitting the overflow to occur. Given the severity and the need for advanced exploitation knowledge, the risk is high for systems that cannot apply the patch promptly. The CVSS score of 8.3 indicates a high severity level.
OpenCVE Enrichment