Impact
An integer overflow was discovered in Chromecast components of Google Chrome versions prior to 152.0.7977.65. The flaw allows a remote attacker who has already compromised the renderer process to craft a malicious HTML page that triggers the overflow, potentially enabling execution of arbitrary code outside the renderer sandbox. This flaw maps to CWE‑190 and can compromise the confidentiality, integrity, and availability of the host system if exploited.
Affected Systems
Google Chrome on desktop devices running version numbers below 152.0.7977.65, with Chromecast functionality enabled. The vulnerability affects all installations of Chrome that include the Chromecast rendering libraries for Windows, macOS, and Linux.
Risk and Exploitability
While the flagged severity in Chromium is labeled High, the CVSS score of 8.3 confirms a high level of risk. Exploitation requires a prior compromise of the renderer process, limiting practical risk to scenarios where an attacker can deliver malicious content that subverts the sandbox. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, but prompt update or restricted use of Chromecast is recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA