Impact
An insufficiency in validating untrusted input in the Chromoting component of Google Chrome on Linux allows a remote attacker who has already compromised a renderer process to craft a malicious Chrome Extension that can potentially escape the sandbox. The weaknesses, identified as CWE‑20 and CWE‑501, could let an attacker gain code execution privileges beyond the browser sandbox, jeopardizing system confidentiality and integrity.
Affected Systems
Google Chrome on Linux systems running any version prior to 149.0.7827.53 is affected. The issue is limited to the desktop (stable channel) releases of Chrome on Linux platforms.
Risk and Exploitability
The CVSS score is 9.6, indicating a critical severity, while the EPSS score of < 1% suggests a low probability of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires a prior renderer process compromise and the inclusion of a crafted extension, making it a medium difficulty attack with limited surface area. If a renderer is already breached, an attacker could escape the sandbox and execute arbitrary code.
OpenCVE Enrichment
Debian DSA