Impact
Script injection in the Headless mode of Google Chrome allows a remote attacker to execute arbitrary code by serving a crafted HTML page. The flaw is a code injection vulnerability (CWE-94) that can compromise confidentiality, integrity, and availability of any system running the affected version. The vulnerability is rated high severity by Chromium security.
Affected Systems
The affected product is Google Chrome in its Headless variant. Versions prior to 149.0.7827.53 are vulnerable, including 149.0.7827.52 and earlier. Users running the stable channel before the mentioned release are at risk.
Risk and Exploitability
Chromium security labels the flaw as high severity. The CVSS score is 8.8. No EPSS score is available and the flaw is not listed in the CISA KEV catalog. A remote attacker can trigger the vulnerability by delivering a malicious HTML page to a Headless Chrome instance, executing code with the privileges of that process. The attack requires that the victim’s system runs an exposed instance of Headless Chrome that processes the attacker‑supplied page.
OpenCVE Enrichment
Debian DSA