Impact
A stack-based buffer overflow exists in the WebGL component of Google Chrome, allowing a remote attacker to execute arbitrary code outside the browser sandbox by serving a specially crafted HTML page. The vulnerability is severe, classified as high severity by Chromium. When triggered, it grants the attacker code execution outside the browser sandbox, potentially enabling data theft, persistence, or further exploitation.
Affected Systems
All users running Google Chrome versions prior to 152.0.7977.65 are affected. This impact spans every operating system where Chrome is installed. Any installation of the affected Chrome release that processes WebGL content is vulnerable.
Risk and Exploitability
The CVE has an EPSS score of < 1% and is not listed in the CISA KEV catalog, though its 9.6 CVSS score indicates a high severity. The likely attack vector involves a user visiting a malicious web page or clicking a link that loads crafted WebGL content, which then overflows the stack and drops an attacker’s payload. Successful exploitation would compromise the entire system, given code executes outside the browser sandbox. While a publicly known exploit is not yet documented, the low EPSS score implies a very low probability of widespread exploitation, though attackers may still craft their own code.
OpenCVE Enrichment
Debian DLA
Debian DSA