Impact
The vulnerability is a type confusion flaw in Chrome's Accessibility layer on Windows. An attacker who manages to compromise the renderer process can craft a malicious HTML page that triggers the flaw, allowing execution of arbitrary code outside the renderer sandbox. This results in remote code execution that can affect the user account or the system, raising both confidentiality and integrity concerns.
Affected Systems
Affected systems are Google Chrome browsers running on Windows platforms with versions earlier than 152.0.7977.65. Any Windows user with these Chrome builds is susceptible to the flaw if an attacker can entice the user to load malicious content.
Risk and Exploitability
The CVE has a CVSS score of 8.3, which indicates high severity, but the EPSS score is < 1% and it is not listed in the CISA KEV catalog, indicating that there are no confirmed public exploits yet. The attack vector is remote via crafted web content, presupposing that the renderer process has already been compromised, which typically requires initial compromise of user input or drives by malicious web pages. Given these prerequisites and the low EPSS score, the likelihood of exploitation is considered moderate, but the potential impact is severe due to code execution outside the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA