Impact
Chrome's Contextual Tasks feature contains a confused deputy bug that lets a remote attacker who has already gained control of the renderer process create a crafted HTML page that tricks the browser into granting a privileged page access to that renderer, bypassing system access restrictions. This gives the attacker the ability to read or modify privileged information or execute privileged code. The Chromium team rated the severity of this flaw as Medium.
Affected Systems
Google Chrome installations running any version prior to 155.0.8059.39 are affected. No other vendors or products are listed as impacted.
Risk and Exploitability
Because the exploit requires that the renderer be compromised first, the probability of an attacker reaching the vulnerable state is limited. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The flaw was classified as Medium severity, indicating a moderate risk when the prerequisites are met. An attacker who succeeds can bypass the browser’s sandbox to access privileged pages.
OpenCVE Enrichment