Impact
Improper input validation – a type of weakness identified as CWE‑20 – in Chrome's Chromecast component allows a remote attacker who has compromised the renderer process to trigger arbitrary code execution outside the sandbox by serving a crafted HTML page. This flaw can lead to full control of the victim machine, compromising confidentiality, integrity, and availability. The Chromium security team rated the vulnerability as Critical.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected. The CVE does not specify which operating systems are impacted, but the vulnerability applies to all instances of Chrome on any OS that run the browser.
Risk and Exploitability
The CVSS score is 8.3, indicating high severity. The EPSS score is < 1% (0.00253) and the vulnerability is not listed in the CISA KEV catalog, yet the Chromium security severity of Critical and the potential for code execution outside the sandbox point to a serious risk. If an attacker can deliver a crafted HTML page and has compromised or gained control over the renderer process, they could execute arbitrary code. The likely attack vector is a web‑based exploit, contingent on the attacker achieving renderer process compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA