Impact
Integer overflow in the GPU component of Google Chrome prior to 149.0.7827.53 allows an attacker who has already compromised the renderer process to escape the browser sandbox, potentially giving full system privileges. The flaw stems from an out‑of‑bounds read (CWE‑125) and a signed integer overflow (CWE‑190). If successfully exploited, an attacker could gain confidentiality, integrity, and availability of the host system.
Affected Systems
All versions of Google Chrome older than 149.0.7827.53 running on Windows, macOS or Linux are affected. The vulnerability is tied to GPU acceleration, so any instance where hardware rendering is enabled is vulnerable, independent of the operating system.
Risk and Exploitability
The EPSS score is 0.00068, indicating a very low probability of exploitation in the general population. The vulnerability is not listed in CISA’s KEV catalog and no public exploits have been reported. Because the flaw requires an attacker to already control the renderer process, the practical risk depends on prior compromise of the browser or a malicious web page. Nevertheless, the potential for a sandbox escape warrants prompt remediation.
OpenCVE Enrichment
Debian DSA