Impact
Improper input validation in the media subsystem of Google Chrome prior to 152.0.7977.65 allows a remote attacker to craft an HTML page that triggers processing of malicious data, potentially executing arbitrary code outside the browser sandbox. This is a classic input validation flaw (CWE-20) that can lead to execution of code with privileges exceeding the sandbox constraints.
Affected Systems
Google Chrome on Windows, macOS, Linux, and other supported platforms in versions earlier than 152.0.7977.65. Any installation that has not applied the August 2026 stable channel update is affected.
Risk and Exploitability
The EPSS score is < 1%, indicating very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog, but the Chromium advisory assigns it a medium severity with a CVSS score of 8.8. Because the flaw permits code execution outside the sandbox, a successful exploit would grant an attacker the same privileges as the browser process. The attack vector is likely a web page or a local HTML file that the user opens, so protection hinges on keeping the browser updated and ensuring sandbox features are not disabled. No public exploit has been confirmed, yet the combination of media handling and input validation weaknesses represents a significant risk for attackers with access to local or remote content.
OpenCVE Enrichment
Debian DLA
Debian DSA