Impact
An out-of-bounds write occurs when the GPU driver in Chrome processes a crafted HTML page. The flaw can allow a remote attacker who has already compromised the isolated GPU process to escape the sandbox and execute arbitrary code. The weakness manifests as a buffer overrun, a classic example of memory corruption that bypasses bounds checking.
Affected Systems
Google Chrome versions prior to 147.0.7727.101 are affected. Any installation of the Chrome browser that uses GPU acceleration and has not yet applied the 147.0.7727.101 update is vulnerable.
Risk and Exploitability
Chromium assigns a high severity to this issue. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, indicating that public exploitation data is limited. The likely attack vector involves serving a malicious HTML page that targets the user’s GPU process; if the attacker already controls the GPU process, they can exploit the write to escape the sandbox. The CVSS score is 8.3.
OpenCVE Enrichment