Impact
Integer overflow in the GPU component of Google Chrome versions prior to 149.0.7827.53 enables an attacker who already controls the renderer process to escape the sandbox, potentially gaining full system privileges. The flaw originates from an out‑of‑bounds read (CWE‑125) during GPU memory handling when a crafted HTML page triggers the vulnerable code path. While the Chromium team rates the vulnerability as low severity, the consequence of a successful escape is complete privilege escalation within the affected machine.
Affected Systems
Google Chrome running on any operating system is affected when the version is older than 149.0.7827.53. In particular, releases before that build on Windows, macOS, and Linux are vulnerable. The issue is tied to GPU acceleration, so all instances that enable hardware rendering are impacted.
Risk and Exploitability
Because the flaw requires an attacker to first gain control of the renderer process, its practical exposure depends on prior compromise of the browser or a malicious webpage. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The reported Chromium security severity is low, and no public exploits have been disclosed. Nonetheless, the potential to escape the sandbox warrants patching or mitigation once an attacker has gained in‑process control.
OpenCVE Enrichment