Impact
The flaw is a numeric truncation error in Chrome’s Media component that can be triggered by a crafted HTML page. When the truncated value is processed, the browser may execute arbitrary code outside the sandbox, granting the attacker the privileges of the browser process. This weakness is classified as CWE‑197, where improper handling of numeric values can lead to loss of precision and unexpected behavior. Although Chromium labels the severity as medium, the sandbox escape elevates the overall risk to a critical level.
Affected Systems
The vulnerability affects Google Chrome browsers on the stable channel that are older than version 153.0.8010.36. It is present on all desktop installations of Chrome released before the update, regardless of operating system. Users running earlier releases are potentially vulnerable when they load a malicious HTML file from an untrusted source.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 9.6 denotes a critical risk. The most likely attack vector is a modified HTML page served over the web or delivered via a local file that the user opens; this inference is based on the description that a crafted HTML file can trigger the defect. Once the page renders, the truncation error can cause the browser process to execute unauthorized code, potentially allowing the attacker to run commands with the privileges of the user—effectively achieving system‑level compromise. No additional mitigation is available beyond updating the browser, so rapid patching is essential.
OpenCVE Enrichment
Debian DLA
Debian DSA