Impact
A buffer overflow exists in the WebRTC component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to trigger arbitrary code execution inside the browser’s sandbox by loading a specially crafted HTML page. The vulnerability is classified with a medium severity by Chromium’s internal review, but the potential for executing code within the sandbox is significant.
Affected Systems
Google Chrome browsers dated before 152.0.7977.65 are affected. The issue is limited to the WebRTC implementation in the stable channel releases, and does not extend to pre‑release or beta tracks beyond the specified version boundary.
Risk and Exploitability
The flaw is exploitable via standard web content delivery; a malicious page can be served over HTTP or HTTPS to a user’s browser. While the attacks are sandboxed, code execution within that sandbox can still lead to privilege escalation in certain contexts. The CVSS score of 8.8 indicates a high severity, and the EPSS score is <1%, reflecting a low but nonzero probability of exploitation. The vulnerability has not been listed in CISA’s KEV catalog. Given the high CVSS score, the risk is elevated and realistic exploitation is possible if a target user visits a malicious page.
OpenCVE Enrichment
Debian DLA
Debian DSA