Impact
The vulnerability is a buffer overflow in the Blink rendering engine of Google Chrome versions prior to 152.0.7977.65. A maliciously crafted HTML page can trigger the overflow when the renderer process parses it, allowing an attacker that has already compromised the renderer to execute arbitrary code inside the renderer’s sandbox. This enables the attacker to run code without the sandbox’s restrictions and potentially gain privileges beyond those of the browser process.
Affected Systems
Vendor: Google; product: Chrome Browser. All releases older than 152.0.7977.65 are affected. No specific minor revisions are listed as vulnerable beyond the general statement that any pre‑152 Chrome is compromised.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a malicious HTML page that the victim opens. The attacker must first compromise the renderer process, which implies the victim must load the crafted content; this raises the barrier compared to a pure remote code execution flaw. Once the renderer is compromised, the attacker can escape the sandbox to execute arbitrary code within the browser context, potentially leading to system compromise if additional privileges are gained.
OpenCVE Enrichment
Debian DLA
Debian DSA