Impact
A flaw in the Base component of Google Chrome on Windows allows an attacker who has already compromised the renderer process to serve a specially crafted HTML page that can escape the browser sandbox. The weakness is an input validation failure (CWE‑20) and involves an improper privilege handling (CWE‑266), which can enable an attacker to gain elevated privileges and potentially compromise the entire system.
Affected Systems
Google Chrome installed on Windows operating systems, for versions on the stable channel earlier than 149.0.7827.53.
Risk and Exploitability
The vulnerability was scored 9.6 on the CVSS scale, indicating high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers must first gain control of the renderer process—typically through a malicious website or compromised plugin—before delivering the malicious HTML, which limits the breadth of exploitation but still poses a significant risk when achieved.
OpenCVE Enrichment
Debian DSA