Impact
An out‑of‑bounds read vulnerability exists in the WebGL implementation of Google Chrome that allows a crafted HTML page to be loaded from a remote site. The flaw can lead to execution of arbitrary code outside the browser sandbox, constituting a high‑severity security issue according to Chromium's internal classification.
Affected Systems
The affected product is Google Chrome. Versions prior to 153.0.8010.36 are potentially vulnerable. The remediation notice refers to the stable channel update to 153.0.8010.36, implying that earlier stable builds contain the flaw.
Risk and Exploitability
The vulnerability can be triggered remotely by a maliciously crafted web page. Attackers can cause a sandbox escape and execute arbitrary code on the client’s machine. The EPSS score is less than 1 percent, indicating a low likelihood of exploitation, but the CVSS score of 9.6 classifies the flaw as Critical and it is not listed in CISA’s KEV catalog. The high severity rating demands prompt action for systems running affected Chrome versions.
OpenCVE Enrichment
Debian DLA
Debian DSA