Impact
Out of bounds memory writes in the GPU component of Google Chrome before version 148.0.7778.216 allow an attacker who has already compromised the renderer process to corrupt memory and potentially escape the renderer sandbox. The flaw is a classic buffer overrun (CWE‑787) that can lead to arbitrary code execution with higher privileges. The vulnerability is not limited to a specific OS, but the CVE description focuses on the renderer process rather than the platform.
Affected Systems
Google Chrome browsers on any operating system that are running a version older than 148.0.7778.216 are affected. The flaw is confined to the renderer process and is triggered by a compromised or maliciously crafted web page. Operating system support is not specified in the CVE data.
Risk and Exploitability
The CVSS score of 8.3 signals high severity, while the EPSS score of less than 1 % indicates a low but non‑zero probability of exploitation. The flaw is not present in the CISA KEV catalog. Exploitation requires first gaining control of the renderer process, which can be achieved through a malicious HTML page or an existing vulnerability in the renderer. Based on the description, it is inferred that the attacker can trigger the flaw via a crafted HTML page, and once the renderer sandbox is escaped, the attacker could run code with elevated privileges on the host.
OpenCVE Enrichment
Debian DSA