Impact
The vulnerability is an integer overflow in the WebRTC implementation of Google Chrome that can be triggered by a crafted HTML page. An attacker who successfully exploits this flaw could cause the browser to execute arbitrary code while remaining inside the sandboxed environment. The flaw is considered a low severity issue by Chromium security but the CVSS score of 8.8 indicates a high severity, and it still provides a pathway for code execution.
Affected Systems
Google Chrome browsers prior to version 152.0.7977.65 on desktop platforms are affected.
Risk and Exploitability
The flaw can be triggered remotely by visiting a malicious web page, so the attack vector is network‑based and requires the user to load the crafted page in Chrome. The CVSS score of 8.8 indicates a high severity, and the EPSS score, though very low at < 1%, suggests limited current exploitation. The vulnerability is not listed in the CISA KEV catalog. The potential for arbitrary code execution makes it a significant risk, albeit in a sandboxed context. No public exploit has been documented, but the nature of the overflow suggests that success is likely if an attacker can supply specially crafted data to the WebRTC component.
OpenCVE Enrichment
Debian DLA
Debian DSA