Impact
A buffer overflow occurs in the GPU subsystem of Google Chrome on Windows. When a renderer process—already compromised or lured into executing a crafted HTML document—processes malicious content, the overflow allows execution of arbitrary code outside the browser sandbox. The flaw is classified as high severity by Chromium. The attacker can gain full control over the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
Windows users running Google Chrome versions earlier than 152.0.7977.75 are vulnerable. Any machine with the desktop Chrome browser installed on Windows and not yet updated to at least this release is susceptible to exploitation.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability. The EPSS score is not available, but high severity already signals a significant risk. Because the vulnerability requires a remote attacker to provide a specially crafted HTML page that triggers the overflow within the renderer process, the most likely attack vector is a malicious website or a compromised site. The flaw is not listed in the CISA KEV catalog, meaning there have been no publicly confirmed exploits yet; however, the high severity and lack of update suggest that exploitation could occur if a suitable payload is delivered.
OpenCVE Enrichment
Debian DLA
Debian DSA