Impact
The vulnerability involves improper input validation in the media component of Google Chrome on Windows. A crafted HTML page can cause the renderer process, when already compromised, to execute code outside the sandbox boundaries. This flaw is a classic bounds‑check failure (CWE-20). The result of a successful exploit would be execution of arbitrary code with the privileges of the renderer process, potentially compromising the host system.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 on Windows are impacted. The issue does not apply to newer releases that have incorporated the patch.
Risk and Exploitability
Exploitation requires a remote attacker to have already gained control of the renderer process, which is a significant prerequisite. The Chromium severity rating is Medium, based on a CVSS score of 7.5, and the EPSS score is <1%, indicating a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Without a prior renderer compromise, the risk of exploitation is low; however, once the renderer is compromised, arbitrary code execution becomes possible.
OpenCVE Enrichment
Debian DLA
Debian DSA