Impact
The vulnerability is a race condition in Chrome's GPU subsystem that allows a remote attacker who has already gained control over a renderer process to execute arbitrary code outside the renderer sandbox by delivering a maliciously crafted HTML page. The flaw lies in the timing of GPU resource handling, classified as CWE-367, and can lead to full code execution on the target system, compromising confidentiality, integrity, and availability.
Affected Systems
Google Chrome operating on any version earlier than 152.0.7977.65. Users who are running an older stable channel build with GPU acceleration enabled are vulnerable until they upgrade to 152.0.7977.65 or a later release that resolves the race condition.
Risk and Exploitability
The problem manifests only when GPU acceleration is active, and an attacker must first compromise the renderer process. The CVSS score of 8.3 labels it high severity, yet the EPSS score of less than 1% indicates a very low probability of real‑world exploitation, and it has not yet been reported in the CISA KEV catalog. Nevertheless, because it allows code execution outside the sandbox, it demands prompt attention from high‑privilege environments, especially where the renderer could be endangering privileged operations.
OpenCVE Enrichment
Debian DLA
Debian DSA