Impact
The vulnerability is a type confusion bug in the CSS parser that allows a remote attacker to execute arbitrary code inside a sandbox by delivering a specially crafted HTML page. Labeled as CWE-843, the flaw can compromise the sandboxed execution environment, potentially leading to privilege escalation or unintended manipulation of the browser state.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 on all supported platforms remain susceptible to this flaw.
Risk and Exploitability
Attackers can exploit this flaw remotely by hosting a malicious page that targets vulnerable Chrome installations. The CVSS score is 8.8; an EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Chromium itself rates the severity as Medium, and users who upgrade beyond the stated version are immune.
OpenCVE Enrichment