Impact
A type confusion flaw in the Media component of Google Chrome allows a remote attacker to execute arbitrary code with sandboxed privileges by delivering a specially crafted HTML page. The vulnerability is classified as high severity and gives the attacker the ability to run code within the browser context.
Affected Systems
Google Chrome desktop versions released before 149.0.7827.53 are affected. The flaw applies to all platforms that run these Chrome releases.
Risk and Exploitability
The CVSS score is 8.8 and the EPSS score is not available, so the severity is high but the likelihood of exploitation is currently undetermined. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit it by causing a victim to load a malicious web page, at which point code execution occurs inside the browser sandbox. No widespread public exploits are reported at the time of analysis.
OpenCVE Enrichment