Impact
An insufficient validation of untrusted input in the media handling path of Google Chrome enables a remote attacker who has already compromised the renderer process to potentially escape the sandbox. The flaw reflects a classic input validation weakness (CWE‑20) and can allow the attacker to execute arbitrary code outside the renderer’s confined environment, potentially compromising the host operating system’s confidentiality and integrity.
Affected Systems
The vulnerability affects desktop editions of Google Chrome prior to version 149.0.7827.53 on all platforms that run that build, including Windows, macOS, and Linux users. Any installation of those earlier versions is at risk if a renderer process is compromised.
Risk and Exploitability
The CVSS assessment indicates high severity, but the EPSS score is not available, so a precise exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a prior foothold in the renderer process, after which a specially crafted HTML page could lead to sandbox escape. Because the flaw can lead to full system compromise and high severity, the overall risk remains significant for affected users.
OpenCVE Enrichment