Impact
The flaw stems from an improper state validation in Google Chrome's Parser module. By loading a specially crafted HTML page, a remote attacker can cause the browser to execute arbitrary code within its sandbox environment. The weakness is categorized as CWE-754.
Affected Systems
All Chrome browsers built before version 152.0.7977.65 are affected. The issue originates in the core parsing logic shared across all platforms, so any installation of Chrome using that build is vulnerable.
Risk and Exploitability
The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA KEV. The CVSS score of 8.8 indicates high severity. The attack vector is remote and requires a victim to visit a malicious web page in an affected Chrome version. Even though no public exploits are known, the window of exposure remains open until the browser is updated. Maintaining the default sandbox and site isolation features provides additional protection, but they do not eliminate the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA