Impact
Out‑of‑bounds write in the GPU component of Chrome on Linux before version 151.0.7922.109 can allow an attacker who has already compromised the renderer process to escape the sandbox via a specially crafted HTML page. This flaw is a classic memory corruption vulnerability (CWE‑787) that can lead to execution of arbitrary code with the privileges of the renderer, potentially elevating to system level if the sandbox boundary is broken.
Affected Systems
The affected product is Google Chrome running on Linux. Any installation of Chrome with builds older than 151.0.7922.109 is vulnerable. Users of the Chrome stable channel before that release are potentially exposed.
Risk and Exploitability
The CVSS score is 8.3, and the Chromium team indicates the severity is high and the flaw can result in full privilege escalation once a renderer process is compromised. The EPSS score is < 1%, and the vulnerability is not in the CISA KEV catalog, so widespread exploitation remains uncertain but possible. The attack requires a remote attacker to supply a crafted HTML page that is rendered by the vulnerable driver, so a pre‑existing compromise of the renderer or network access to a vulnerable user’s browser is necessary.
OpenCVE Enrichment
Debian DLA
Debian DSA