Impact
An integer overflow in Google Chrome’s Dawn graphics engine can occur when parsing a specially crafted web page. Based on the description, it is inferred that a malicious web page delivered through a browser’s renderer that has already been compromised may trigger the overflow, potentially leading to a sandbox escape, allowing code execution outside the browser sandbox and possibly on the host operating system. The issue is grouped under CWEs 190 and 472.
Affected Systems
The affected product is Google Chrome. Versions identified in the advisory are those older than 149.0.7827.53. The vulnerability could impact any platform that runs the affected Chrome build, including macOS, Linux, and Windows.
Risk and Exploitability
The CVSS score of 8.3 denotes high severity, while the EPSS score of <1% signals a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation likely requires an attacker to trick a user into loading a malicious page that triggers the integer overflow, which would then allow a slide from renderer process compromise to sandbox escape and potential remote code execution at elevated privileges. Because the exploitation path is specific, widespread attacks are presently considered unlikely.
OpenCVE Enrichment
Debian DSA