Impact
Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome allows a remote attacker who has already compromised the renderer process to escape the sandbox. The flaw stems from improper input validation (CWE‑20) and could enable the attacker to execute arbitrary code with the renderer’s privileges, potentially compromising the entire system if privilege levels are not adequately restricted.
Affected Systems
Google Chrome desktop in the stable channel is affected. The vulnerability exists in releases prior to 149.0.7827.53. Specific affected versions beyond this threshold have not been listed, so any version before the mentioned cutoff should be considered vulnerable.
Risk and Exploitability
The base severity is classified as Medium. No EPSS value is available and the CVE is not listed in CISA’s KEV catalog, indicating a moderate likelihood of exploitation. The attack requires an attacker who has already gained control over a renderer process to craft a malicious HTML page. While the path is not trivial, the absence of widespread exploitation makes the immediate risk moderate; however, the potential for full system compromise remains if the escape succeeds.
OpenCVE Enrichment