Impact
Google Chrome on Windows lacks proper validation for untrusted input in its printing component, enabling an attacker who has already compromised the renderer process to craft a malicious HTML page that may trigger a sandbox escape. The impact is a potential escalation of privileges or execution of arbitrary code on the host system, as the attacker could break out of the renderer sandbox and reach higher privileged processes.
Affected Systems
The issue affects Google Chrome versions prior to 149.0.7827.53 when running on Windows. Any system with this browser version installed is susceptible until the patch is applied.
Risk and Exploitability
The CVE is listed as high severity by Chromium, yet EPSS data is unavailable and it is not in the CISA KEV catalog. Exploitation requires the attacker to compromise the renderer process, likely through a malicious website or local content. Once the renderer is tainted, the crafted HTML can exploit the input validation flaw to escape the sandbox, potentially leading to full system compromise. While actual widespread exploitation has not been reported, the combination of a high severity rating and the ability to escape the sandbox signifies a significant risk to affected users.
OpenCVE Enrichment