Impact
Buffer overflow in the Network component of Google Chrome prior to 151.0.7922.173 can be triggered by a crafted HTML page. The flaw allows a remote attacker to execute arbitrary code outside the browser sandbox, giving full system compromise. The weakness is identified as CWE-122.
Affected Systems
The vulnerability affects Google Chrome. No specific version ranges are listed other than the mentioned pre‑151.0.7922.173 threshold.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is < 1%, suggesting low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the lack of evidence of exploitation does not reduce the need for a patch. Attackers would need to obtain a specially crafted HTML page loaded in the browser, which can be delivered via a malicious website or email attachment, providing a straightforward remote code execution path.
OpenCVE Enrichment
Debian DLA
Debian DSA