Impact
The vulnerability arises from incomplete cleanup in the Dawn rendering engine in Google Chrome versions prior to 155.0.8059.39. A crafted HTML page can trigger code execution outside the sandbox, allowing an attacker to run arbitrary code on the affected system. The weakness maps to CWE-459 (Improper Output Neutralization for Security-related Data).
Affected Systems
Affected products are Google Chrome browsers used on desktop platforms. Users with any Chrome build older than 155.0.8059.39 are potentially vulnerable. The most recent secure release is 155.0.8059.39 and later.
Risk and Exploitability
The CVE is rated as medium severity in Chromium's own scoring, and its EPSS score is not available, meaning the recent exploitation probability is unknown. It is also not listed in the CISA KEV catalog. Externally, the attack requires a user to open a maliciously crafted HTML page, so it is a remote attack that could be delivered via phishing or compromised websites. Because the flaw bypasses the sandbox, successfully exploited code could perform any action with the privileges of the browser process.
OpenCVE Enrichment