Impact
The vulnerability is an improper input validation flaw in the Media component of Google Chrome before version 152.0.7977.65. A malicious actor can craft a specially formatted HTML page that, when opened by a user, may lead to the execution of arbitrary code outside the browser's sandbox. This permits full compromise of the affected system. The flaw is classified by Chromium as a Medium severity issue, but the CVSS score of 8.8 indicates a high impact.
Affected Systems
Google Chrome on desktop platforms running any version earlier than 152.0.7977.65 is affected. The vulnerability originates in the Media subsystem, which processes multimedia content presented in HTML pages.
Risk and Exploitability
Because the exploit requires a user to open a crafted HTML page, exploitation is remote but opportunistic. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread exploitation has not yet been observed. The CVSS score of 8.8 and the classification of remote code execution suggest a high risk if an attacker can convince a user to visit a malicious page, although it does not represent an automatically exploitable flaw like server-side vulnerabilities.
OpenCVE Enrichment
Debian DLA
Debian DSA