Impact
A buffer overflow in the Media component of Google Chrome allows a remote attacker to craft a malicious HTML page that triggers the overflow and enables execution of arbitrary code within the sandbox. The flaw is a classic buffer overflow (CWE‑122) affecting data handling in media processing. This violation of memory safety can lead to remote code execution, potentially allowing an attacker to take control of the browser context and compromise the user system.
Affected Systems
All users of Google Chrome browsers using versions prior to 152.0.7977.65 are affected, including stable channel releases below that version. The vulnerability is present in the Media component and impacts all platforms supported by Chrome at the time of the release.
Risk and Exploitability
The vulnerability receives a high severity rating with a CVSS score of 8.8, and the EPSS score is less than 1%, but because it can be triggered remotely via user navigation to a crafted page, the likelihood of exploitation is moderate. The flaw is not yet listed in the CISA KEV catalog. An attacker would need only a simple malicious web page to deliver the payload, exploiting the buffer overflow to escape the sandbox. Because the vulnerability operates inside the sandbox, the initial scope is limited to the browser process, but privilege escalation could still occur if the sandbox bypasses succeed.
OpenCVE Enrichment
Debian DLA
Debian DSA