Impact
An out-of-bounds read bug in the Dawn rendering engine of Google Chrome allows a remote attacker who has already compromised a renderer process to potentially escape the browser sandbox by loading a specially crafted HTML page. This flaw can lead to execution of arbitrary code outside the controlled sandbox, compromising confidentiality and integrity of the user’s system. The vulnerability is classified with a high severity rating by Chromium.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 are affected. The issue resides in the Dawn renderer used across all desktop platforms that include these Chrome releases. Any user running a vulnerable build is potentially exposed.
Risk and Exploitability
No EPSS value is available, and the flaw is not listed in the CISA KEV catalog. Attackers would need to first obtain code execution inside the renderer process and then exploit the out-of-bounds read gadget; thus the vector is somewhat constrained. Once the sandbox is escaped, the attacker could gain arbitrary system access. Given the high severity and lack of public exploitation evidence, organizations should treat this as a high risk and apply the update promptly.
OpenCVE Enrichment