Impact
The flaw is a heap buffer overflow in the CrashReporting component of Google Chrome that exists in all releases prior to 151.0.7922.109. An attacker who has already compromised the renderer process can trigger the overflow using a crafted HTML page, which creates the possibility of a sandbox escape and thus arbitrary code execution. The weakness corresponds to classic heap corruption patterns, identified as CWE-120 and CWE-122, and is classified as high severity by Chromium’s security team.
Affected Systems
Google Chrome browsers on all platforms that run version 151.0.7922.108 or earlier are vulnerable. The vulnerability is tied only to the Chrome binary version, not to particular hardware or user configurations.
Risk and Exploitability
The description indicates that a remote attacker must first compromise the renderer process to exploit the overflow. Once that occurs, the vulnerability can be leveraged for a sandbox escape, which is a severe privilege‑escalation scenario. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not widely exploited yet. The CVSS score of 8.3 indicates high severity.
OpenCVE Enrichment
Debian DLA
Debian DSA