Impact
An integer overflow in the GPU driver of Google Chrome on Linux and ChromeOS allows a remote attacker with control over the renderer process to potentially escape the sandbox. The weakness is classified as CWE-472, indicating improper arithmetic handling that can change program logic, and it also meets the definition of CWE-190, an integer overflow that can corrupt program logic.
Affected Systems
Google Chrome versions prior to 148.0.7778.168 on Linux and ChromeOS are affected. The issue originates specifically from the GPU component of the renderer process, so any installation of Chrome below the mentioned version running on these platforms is vulnerable.
Risk and Exploitability
The launch of this vulnerability is considered highly severe, with a CVSS score of 8.3 and the Chromium project rating it high. The exploit requires an attacker to compromise the renderer process and craft a malicious HTML page; the attack vector is likely remote via a web page or a compromised site. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the risk remains significant for systems with outdated Chrome versions, while newer releases inherently mitigate the problem.
OpenCVE Enrichment
Debian DSA