Impact
A stack buffer overflow in the GPU component of Google Chrome allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. The overflow is triggered by a crafted HTML page, giving the attacker the potential to escape the renderer sandbox and execute code in a higher privilege context within the browser process. The weakness is a classic stack‑based buffer overflow, identified as both CWE‑120 and CWE‑121.
Affected Systems
Google Chrome desktop builds prior to version 149.0.7827.53 on all platforms that include the GPU process. Users running any older stable channel release are affected and should upgrade to the latest available build.
Risk and Exploitability
Chromium security severity is listed as Critical. The EPSS score is <1% and the vulnerability is not in CISA KEV. The exploit would require first delivering a malicious HTML page that loads in a compromised renderer. The likely attack vector is a user visiting or interacting with a malicious website, permitting the overflow to occur. Given the severity and the need for advanced exploitation knowledge, the risk is high for systems that cannot apply the patch promptly. The CVSS score of 8.3 indicates a high severity level.
OpenCVE Enrichment
Debian DSA