Impact
An improper input validation flaw (CWE-20) in the Media component of Google Chrome before 152.0.7977.65 can allow a remote attacker to potentially execute arbitrary code outside the browser sandbox by delivering a specially crafted HTML page. The vulnerability is rated high by Chromium and could compromise confidentiality, integrity, and availability by giving the attacker system‑level access.
Affected Systems
All users running Google Chrome versions older than 152.0.7977.65 are affected, regardless of operating system. This includes the stable channel of Chrome on desktop platforms.
Risk and Exploitability
With a CVSS score of 9.6, the vulnerability is rated high severity. The attack vector is remote via a web page, requiring the victim to load the malicious content. The EPSS score of 0.0035 indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. At this time there are no known public exploit samples, but the potential for exploitation remains high due to the remote nature and lack of a sandbox bypass prevention in affected releases.
OpenCVE Enrichment
Debian DLA
Debian DSA