Impact
Insufficient validation of untrusted input in the Media module of Google Chrome on Windows permits a remote attacker who has already compromised the renderer process to craft an HTML page that may escape the browser sandbox. The vulnerability arises from inadequate input validation (CWE‑20) and weaknesses in media handling that allow the sandbox to be bypassed (CWE‑1286). No additional capabilities beyond breaking out of the sandbox are specified in the description.
Affected Systems
Google Chrome for Windows users running any version before 149.0.7827.53 are affected. The issue applies to the Windows rendering engine and media handling components in these releases.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity, while the EPSS score of < 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog and no public exploits are known. With the requirement that the attacker already control the renderer process, remediation of the flaw remains a high priority due to the potential for a sandbox escape.
OpenCVE Enrichment
Debian DSA