Impact
The vulnerability arises from insufficient validation of untrusted input in the Chromoting component of Google Chrome. A crafted HTML page can allow a remote attacker who has already compromised the renderer process to potentially perform a sandbox escape, thereby gaining higher privileges within the browser environment. The flaw is a CWE‑20 input validation issue and is also associated with CWE‑349, with a reported Chromium severity of Medium.
Affected Systems
Google Chrome is affected when the version is older than 149.0.7827.53. Users running any earlier release are thus exposed to the described risk until they upgrade.
Risk and Exploitability
EPSS Score is < 1% and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 9.6 indicates high severity. Exploitation requires the attacker to have already compromised the renderer process and to serve a malicious HTML page that can overflow the input validation. The attack path relies on a compromised browser sandbox and is therefore considered a high‑risk scenario for users who have not yet applied the patched release.
OpenCVE Enrichment
Debian DSA