Impact
This vulnerability is an integer overflow in the WebGL subsystem of Google Chrome that may allow a remote attacker to run code outside the browser sandbox. The overflow can be triggered by a specially crafted HTML page, and if exploited the attacker could gain full control of the victim’s machine. The issue is rated as medium severity in Chromium’s internal scoring system.
Affected Systems
Google Chrome on all platforms before version 152.0.7977.65 is affected. The vulnerability has been identified for the stable release stream. Users running earlier releases of Chrome on desktop or mobile devices are potentially impacted.
Risk and Exploitability
Because the flaw requires a malicious HTML document to be loaded in the victim’s browser, it is a client‑side exploitation. The EPSS score is 0.00252, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the ability to escape the sandbox makes the risk significant for any user who opens untrusted web content. The CVSS score of 8.8 indicates a high severity, and the medium rating from Chromium suggests that the flaw could be exploited successfully in a realistic scenario.
OpenCVE Enrichment
Debian DLA
Debian DSA