Impact
Improper privilege management in the navigation component of Google Chrome prior to version 152.0.7977.65 allows a remote attacker who has already compromised the renderer process to use a crafted HTML page and social engineering techniques to execute code outside the browser sandbox. The flaw is a classic example of improper privilege management (CWE‑269) and can lead to arbitrary code execution with the privileges of the renderer process or even higher if the sandbox is bypassed.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 are affected. Any installation of Google Chrome that has not yet been updated to the 152.0.7977.65 release contains the vulnerable navigation logic and can be exposed to a malicious webpage.
Risk and Exploitability
According to Chromium, the vulnerability carries a CVSS score of 8.3. The EPSS score of < 1% indicates the exploitation probability is low, and the flaw is not listed in the CISA KEV catalog. The absence of a publicly known exploit and the CVSS score of 8.3 suggest that the overall risk is high, but the potential impact of sandbox escape warrants prompt action.
OpenCVE Enrichment
Debian DLA
Debian DSA