Impact
The vulnerability is an input validation flaw in the Dawn rendering engine of Google Chrome before version 152.0.7977.65. A crafted HTML page can cause the browser to bypass its sandbox and execute arbitrary code outside the browser process. This allows a remote attacker to gain full system access, read or modify files, steal credentials, or compromise any network traffic the user initiates. The weakness corresponds to CWE‑20.
Affected Systems
All supported operating systems running Google Chrome versions prior to 152.0.7977.65 are impacted, an inference based on the CVE description. This includes Windows, macOS, Linux, and other platforms for which Chrome has a stable channel release. Users who have not installed the 152.0.7977.65 update remain at risk.
Risk and Exploitability
The CVSS score of 9.6 marks the flaw as critical. The EPSS score of less than 1% indicates that exploitation is currently rare but possible. The vulnerability is not listed in the CISA KEV catalog, but the impact is severe. Attackers can trigger the exploit simply by hosting a malicious HTML page that a victim visits; no further privileges are needed. Organizations should treat this as an urgent security concern, especially where automatic updates are disabled.
OpenCVE Enrichment
Debian DLA
Debian DSA