Impact
A type confusion flaw in the GPU code path of Google Chrome can be triggered by a specially crafted HTML page when an attacker has already compromised the renderer process. The malicious page causes the renderer to treat data of the wrong type, allowing a sandbox escape that can elevate privileges and potentially give the attacker unrestricted access to the underlying operating system. This vulnerability is classified as CWE-843, type confusion.
Affected Systems
This issue affects Windows versions of Google Chrome prior to release 149.0.7827.53. No other vendors or products are listed as vulnerable.
Risk and Exploitability
Chromium rates this flaw as medium severity, but the CVSS score of 9.6 indicates a critical risk. The EPSS score is <1%, suggesting a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack requires a remote attacker who can deliver a malicious HTML page to an already compromised renderer process; once the type confusion leads to a sandbox escape, the attacker can gain full system control. Without a patch, the risk remains significant for systems running the affected Chrome versions.
OpenCVE Enrichment
Debian DSA