Impact
An integer overflow flaw in the WebRTC component of Google Chrome lets a remote attacker read arbitrary memory inside the browser’s sandbox through a crafted HTML page. The vulnerability is classified as CWE‑190 and was rated Medium by Chromium security reviewers. If exploited, an attacker could obtain sensitive information from a user’s system or use the read data as a foothold for further attacks.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 under the stable channel are vulnerable. Any installation that has not applied the update remains at risk.
Risk and Exploitability
The likely attack vector is a malicious website that serves a specially crafted HTML payload; the victim must visit the site with Chrome for the overflow to occur. The EPSS score is less than 1%, and the issue is not listed in CISA’s KEV catalog, indicating that exploit activity is currently low. The CVSS score of 4.3 places this vulnerability in the medium severity range, suggesting a moderate likelihood of exploitation if an attacker can deliver the payload.
OpenCVE Enrichment
Debian DLA
Debian DSA