Impact
Google Chrome versions before 152.0.7977.65 permitted a remote attacker, once the renderer process has been compromised, to escape the sandbox by manipulating the media workflow. The flaw, classified as CWE‑841, allows code execution outside the browser’s confined environment, giving the attacker full control over the host system.
Affected Systems
All installations of Google Chrome with a version number lower than 152.0.7977.65 are affected. The flaw surfaces only when the attacker can already run code in the renderer process; the error lies in the enforcement of media handling policies.
Risk and Exploitability
The CVSS score of 7.5 denotes a Medium–High severity. The EPSS score of <1% indicates a very low but non‑zero probability of exploitation in the wild, and the vulnerability is not currently listed in CISA's KEV catalog. Attackers must first compromise the renderer before the sandbox escape can be triggered, but once this prerequisite is met, the attack yields high‑impact code execution on the affected system.
OpenCVE Enrichment
Debian DLA
Debian DSA