Impact
Improper resource control in Chrome’s Linux Toolkit Theming lets an attacker who has compromised the renderer process execute arbitrary code outside the sandbox by loading a specially crafted HTML page. The flaw is classified as high severity and is associated with CWE‑708 and CWE‑913, indicating an integrity of resource management weakness that can lead to code execution.
Affected Systems
The vulnerability applies to Linux builds of Google Chrome with versions earlier than 151.0.7922.173. Only users running these older Chrome releases on Linux are susceptible; no other operating systems or vendors are affected.
Risk and Exploitability
The EPSS score of < 1% indicates a low likelihood of widespread exploitation, and the flaw is not listed in the CISA KEV catalog. However, the CVSS score of 8.8 signals high severity. The likely attack vector requires an attacker to first gain renderer‑process privileges, after which a malicious web page triggers the resource control failure, allowing code to run outside the sandbox. Even with a low EPSS, the combination of high severity and the need for a pre‑existing compromise makes the risk significant until a patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA