Impact
The vulnerability is an out‑of‑bounds read in the Media component of Google Chrome before version 153.0.8010.36. The flaw can be triggered by a specially crafted HTML page that causes the browser to read memory outside the bounds of a buffer, leading to arbitrary code execution inside the sandbox. This allows a remote attacker to run code with the privileges of the browser process, potentially breaking the sandbox and compromising the system.
Affected Systems
All desktop users of Google Chrome on Windows, macOS, and Linux who have not upgraded past version 153.0.8010.36 are affected. The issue is present in the stable channel and applies to all revisions of the browser that include the vulnerable Media code.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation, while the CVSS score of 8.8 signifies a high severity vulnerability. Because the vulnerability can be exploited via a crafted HTML page, the likely attack vector is a web‑based attack, such as a malicious site or a phishing email containing a malicious link. Chromium labels the severity as High, and although the vulnerability is not listed in the CISA KEV catalog, the ability to execute arbitrary code remotely makes it a significant risk for any user who visits untrusted web content.
OpenCVE Enrichment
Debian DLA
Debian DSA