Impact
The vulnerability arises from insufficient control flow management in Chrome’s DevTools. A remote attacker can exploit this by delivering a crafted HTML page that triggers the flaw, allowing arbitrary code execution within the browser’s sandbox. The weakness revolves around improper control flow handling, classified as CWE-691, and the Chromium team rated the severity as Medium.
Affected Systems
Affected users are those using Google Chrome versions earlier than 152.0.7977.65 across all supported operating systems. The issue is present in the stable channel, and the referenced Chrome release note indicates a patch is available for these versions.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity, and the EPSS score is less than 1%, implying a low but nonzero likelihood of exploitation. The vulnerability can be leveraged via social engineering; a crafted HTML page can trigger the flaw in DevTools, allowing arbitrary code execution within the browser's sandbox. While the sandbox limits impact, if a sandbox escape occurs, system security could be compromised. Although not listed in the CISA KEV catalog, the high severity warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA