Impact
The vulnerability arises from insufficient validation of untrusted input in the InterestGroups feature of Google Chrome before version 149.0.7827.53. A remote attacker who has compromised the renderer process can serve a crafted HTML page that triggers a sandbox escape, allowing code to execute with higher privileges. This flaw is an example of improper input validation (CWE‑20) and provides the potential for remote code execution.
Affected Systems
Vulnerable for all versions of Google Chrome older than 149.0.7827.53.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity flaw, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. Exploitation requires a compromised renderer process; an attacker can deliver the malicious content via a website or similar. Although no public exploit is documented, the high severity and the ability to escape the sandbox mean the potential impact remains severe, warranting prompt remediation.
OpenCVE Enrichment