Impact
Insufficient validation of untrusted input in USB input handling within Google Chrome allows a remote attacker to execute arbitrary code by delivering a specially crafted HTML page. The vulnerability is categorized as CWE‑20, CWE‑1289, and NVD-CWE-noinfo, indicating insufficient input validation and related weaknesses. A successful exploit would compromise confidentiality, integrity, and availability on the affected system by running arbitrary code with the privileges of the user running Chrome.
Affected Systems
Google Chrome versions prior to 148.0.7778.216 on desktop platforms are affected. Users of these Chrome builds are susceptible to exploitation unless the browser is updated beyond the stated version.
Risk and Exploitability
The weakness permits arbitrary code execution, a high severity outcome with a CVSS score of 8.8. The attack vector is inferred to be remote, whereby an attacker serves a malicious HTML document that manipulates USB input handling; the user must visit or load the page in Chrome. The EPSS score is 0.00078, indicating a very low but non-zero exploitation probability; the lack of a KEV listing does not diminish the risk. Administrators should treat this vulnerability as an immediate threat until it is remediated.
OpenCVE Enrichment