Impact
An out‑of‑bounds write in the Media component of Google Chrome, present in versions prior to 153.0.8010.36, permits a remote attacker to craft a malicious HTML page that triggers memory corruption. The flaw, classified as CWE‑787, can lead to execution of arbitrary code outside the browser sandbox, potentially compromising the host system.
Affected Systems
All users running Google Chrome versions earlier than 153.0.8010.36 are affected. The operating system is not explicitly stated; it may potentially be any OS supported by Chrome. The vulnerability specifically targets the Media handling subsystem.
Risk and Exploitability
The EPSS score of <1% indicates a very low probability of exploitation. The CVSS score is 9.6, indicating critical severity, and the flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be remote – an adversary can drive a victim’s browser to a malicious web page to exploit the vulnerability. Because the flaw allows escape from the sandbox, the potential impact is significant for users browsing the internet.
OpenCVE Enrichment
Debian DLA
Debian DSA