Impact
Memory corruption in Chrome’s codec implementation allows a remote attacker to run arbitrary code inside the browser sandbox through a crafted HTML page. The flaw is a classic out-of-bounds write (CWE‑119, CWE‑787), classified by Chromium as a high‑severity vulnerability.
Affected Systems
Google Chrome versions earlier than 153.0.8010.36 are vulnerable. Any user who visits a malicious web page while using one of these versions is at risk.
Risk and Exploitability
The vulnerability's severity is high, with a CVSS score of 8.8, but its exploit probability is not quantified by EPSS and it is not yet listed in CISA’s KEV catalog. Because the attack vector is a web page accessed by users, the risk to all Chrome users is substantial until the update is applied. The flaw can be exploited remotely without additional credentials, requiring only that the victim load a maliciously crafted page.
OpenCVE Enrichment
Debian DLA
Debian DSA