Impact
Insufficient validation of untrusted input in Google Chrome extensions allowed a privileged escalation when a renderer process is compromised, enabling an attacker to execute code beyond the normal sandbox. The vulnerability stems from insufficient input validation (CWE-20) and leads to privilege escalation (CWE-807). The Chromium project rates the vulnerability as Medium severity.
Affected Systems
Google Chrome is affected on all builds before version 149.0.7827.53. No additional affected products or specific versions are noted beyond the latest revision mentioned.
Risk and Exploitability
The exploit requires a renderer process to be already compromised, typically through a malicious extension or another vulnerability. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The Chromium severity rating of Medium suggests moderate risk, though an attacker could gain elevated privileges within the browser or operating system if successful.
OpenCVE Enrichment
Debian DSA