Impact
A buffer overflow occurs in the GPU component of Google Chrome on Windows. When a renderer process—already compromised or tricked—processes a specially crafted HTML page, the overflow allows execution of arbitrary code outside the browser sandbox. This fault is categorized as a high severity vulnerability in Chromium’s own assessment, indicating a significant threat to confidentiality, integrity, and availability of the affected system.
Affected Systems
The flaw affects Windows users running Google Chrome versions earlier than 152.0.7977.75. Any machine with the desktop Chrome browser installed on Windows and not yet updated to at least this release is vulnerable.
Risk and Exploitability
The EPSS score is not available, but the high severity classification indicates a serious risk. Because the exploit relies on a remote attacker delivering crafted HTML that triggers the overflow within the renderer process, the most likely attack vector is a malicious web page or a compromised site. The vulnerability is not listed in the CISA KEV catalog, meaning there have been no publicly confirmed exploits yet, though the lack of EPSS data does not preclude future exploitation. Systems that have not yet applied the patch remain at risk of remote code execution.
OpenCVE Enrichment