Impact
A type confusion bug in the Animation component of Google Chrome allows a crafted HTML page to trigger the browser to run code inside its sandbox. The flaw stems from improper type handling and could let an attacker compromise the confidentiality, integrity, or availability of the system by executing code with the user’s privileges. The impact is a potential escape from the browser sandbox and execution of code.
Affected Systems
Google Chrome builds prior to version 152.0.7977.65 are affected. Any user running an older Chrome that processes a maliciously crafted HTML page is at risk.
Risk and Exploitability
Chromium rates the vulnerability as high severity with a CVSS score of 8.8. The EPSS score is under 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to entice a user to view or download a maliciously crafted HTML page. The exploit therefore depends on user interaction and does not require local privilege escalation, making it an opportunistic, network–level attack.
OpenCVE Enrichment
Debian DLA
Debian DSA