Impact
Insufficient validation of untrusted input in the Enterprise Reporting component of Google Chrome allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox using a crafted HTML page. The flaw, identified as a CWE‑1289 input validation weakness, could enable the attacker to execute code with the privileges of the renderer process, which may be elevated beyond normal user rights if the sandbox escape succeeds.
Affected Systems
All desktop releases of Google Chrome prior to version 149.0.7827.53 are affected. No other products or newer Chrome versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 9.6 denotes a very high baseline severity, while the EPSS score of less than 1% indicates that exploitation is considered rare at present. The vulnerability is not included in the CISA KEV catalog. An attack requires the attacker to first compromise the renderer process, after which a crafted HTML page enables a sandbox escape that could lead to code execution with renderer privileges or higher. No evidence suggests broader exploitation beyond this scenario.
OpenCVE Enrichment
Debian DSA