Impact
An out‑of‑bounds write flaw exists in Crashpad, the crash‑reporting component of Google Chrome. By loading a specially crafted HTML page, an attacker who has already compromised the renderer process can cause Crashpad to write data beyond allocated buffers, enabling execution of arbitrary code outside the sandbox. The affected component is judged a high‑severity issue in Chromium's own assessment.
Affected Systems
Google Chrome on Windows is affected for all releases earlier than version 152.0.7977.65. The vulnerability is specific to the Crashpad engine that runs in the renderer process on the Windows platform. Users running the stated versions of Chrome on Windows must verify until the next update.
Risk and Exploitability
The flaw allows an attacker to execute code with the privileges of the renderer process once a renderer is compromised. The attack requires delivery of a malicious HTML page to a victim’s browser, so it is a remote attack vector that can be achieved over the network. The CVSS score of 8.3 indicates high severity, while the EPSS score of less than 1% suggests a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The Chromium security severity is high, indicating that exploitation could lead to full system compromise if the renderer can escape its sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA