Impact
An integer overflow in the Chromium engine allows a remote attacker to read portions of memory inside the browser sandbox by delivering a specially crafted file. The flaw does not grant arbitrary code execution; it merely provides a data disclosure that could be leveraged to further compromise a victim. The weakness is identified as a classic integer overflow (CWE‑190).
Affected Systems
Version numbers earlier than 152.0.7977.65 of the Google Chrome web browser on any operating system are susceptible. The fix was released in the stable channel update referenced in the provided documentation, and all subsequent releases thereafter contain the patch.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity, while the EPSS score is below 1%, reflecting a very low probability of exploitation. Because the vulnerability requires the user to open a malicious file with Chrome still running, it is considered a user‑interaction remote attack vector. The flaw is not present in the CISA KEV catalog. Although exploitation likelihood is low, the high severity and potential for data leakage make patching imperative.
OpenCVE Enrichment
Debian DLA
Debian DSA