Impact
The vulnerability is a type confusion flaw, CWE-843, in the Compositing component of Google Chrome. A crafted HTML page can trigger the confusion, allowing a remote attacker to execute arbitrary code inside the browser sandbox. This bypass moves code execution from the confined sandbox into the full browser process, giving the attacker complete control over the host user’s machine. The potential impact includes full confidentiality and integrity compromise and the ability to install malware or capture credentials.
Affected Systems
Google Chrome installations on desktop platforms running any version earlier than 152.0.7977.82 are affected. The flaw exists in the stable channel prior to the release of 152.0.7977.82.
Risk and Exploitability
Because the flaw is triggered by remote HTML content, the attack vector is through the internet via a malicious web page or document. The CVSS score of 8.8 indicates a high severity vulnerability, and the Chromium team rated the severity as High. Exploit probability is currently unknown due to the lack of EPSS information, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, a successful exploitation would provide the attacker with uncontrolled execution privileges within the browser, likely escalating to system‑level access.
OpenCVE Enrichment
Debian DLA
Debian DSA