Impact
The vulnerability results from insufficient validation of untrusted input in DevTools, enabling a remote attacker who has already compromised the renderer process to inject arbitrary scripts or HTML, which could then execute malicious code within the renderer’s context. Based on the description, it is inferred that the attacker must obtain execution rights in the renderer process before injection can occur, leading to potential compromise of the user session or sensitive data.
Affected Systems
Google Chrome versions older than 149.0.7827.53 on desktop platforms (Windows, macOS, Linux) are affected; the issue is confined to the Chrome browser itself and does not impact other system components.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate numeric score, but Chromium's own security severity rating for this issue is High, highlighting a significant risk to users. The EPSS score of < 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA KEV, and exploitation requires an attacker to first gain control of the renderer process, likely through a malicious web page or a separate vulnerability. The likely attack vector, therefore, involves a compromised renderer context; as no public exploits have been documented, the risk remains limited to environments where such renderer code execution is possible.
OpenCVE Enrichment
Debian DSA