Impact
A buffer overflow in the WebGL implementation of Google Chrome allows a remote attacker to execute arbitrary code outside the browser’s sandbox by serving a specially crafted HTML page. The vulnerability is classified as Critical by Chromium security and would grant the attacker full control of the system on which the browser is running.
Affected Systems
All instances of Google Chrome older than version 153.0.8010.36 are affected irrespective of operating system. The vulnerability remains present in any build that contains the older WebGL code path.
Risk and Exploitability
The EPSS score for this issue is less than 1%, and it is not listed in CISA’s KEV catalog, while the vulnerability’s CVSS score is 9.6. Because the flaw can be triggered by any reachable web page, the attack vector is most likely remote over the network, and an attacker can bypass the sandbox whenever a user opens a malicious page. Given the severity and lack of a mitigated path, the potential impact is high.
OpenCVE Enrichment
Debian DLA
Debian DSA