Impact
Incorrect authorization in the Chrome sandbox allows a remote attacker who has already compromised the renderer process to execute arbitrary code outside the sandbox. This flaw effectively removes the security boundary that contains renderer activity, enabling the attacker to run malicious code with the privileges of the browser process. The weakness is an improper authorization flaw (CWE‑863) and the stated Chromium severity is High.
Affected Systems
The vulnerability applies to Google Chrome browsers that are earlier than version 152.0.7977.65. Version information is limited to the pre‑152.0.7977.65 release series, so any older release may be affected. No specific build or patch list is supplied beyond the cutoff.
Risk and Exploitability
At the time of analysis the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 8.3, indicating a high severity, and the intrinsic Chromium severity is High, implying a serious risk. Exploitation requires the attacker to first compromise the renderer process and then deliver a specially crafted HTML page. While the exact likelihood of exploitation is not quantified, the high severity and remote code execution nature suggest that the threat is significant for exposed systems.
OpenCVE Enrichment
Debian DLA
Debian DSA