Impact
Buffer overflow in the WebRTC component of Google Chrome prior to version 153.0.8010.36 allows an attacker to craft a malicious HTML page that, when opened by a user, triggers the overflow and enables arbitrary code execution within the browser’s sandbox. The flaw is a classic buffer overflow (CWE-122) and can potentially be leveraged to escape the sandbox, giving an attacker full control of the host system.
Affected Systems
Users running Google Chrome versions earlier than 153.0.8010.36 are affected. The vulnerability applies to all operating systems where Chrome is available and is present in the stable channel release. Those who have upgraded to at least 153.0.8010.36 have the fix applied.
Risk and Exploitability
The exploit requires a user to be lured to a malicious web page, making it a remote code execution threat that is limited to the browser context unless sandbox escape techniques are employed. The CVSS score of 8.8 indicates a high severity. However, the EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, meaning no known active exploitation has been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA