Impact
In Google Chrome for Windows, a flaw in the PlatformIntegration component permits a remote attacker to force a user to perform specific UI gestures so that a malicious file is handled, leading to arbitrary code execution within the browser. The weakness stems from insufficient input validation (CWE‑20) and unsanitized code execution paths (CWE‑94). Because the code runs with the browser process privileges, the attacker can execute any code that the operating system allows.
Affected Systems
Users running the Google Chrome stable channel on Windows with a build older than 149.0.7827.53 are affected. The vulnerability was fixed in Chrome version 149.0.7827.53 and later; no other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.8 characterizes the flaw as medium severity, while an EPSS score of less than 1 % indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires user interaction through convincing UI gestures after a malicious file has been downloaded or opened, so the practical risk remains limited unless the user cooperates. Once triggered, arbitrary code can run in the browser context, providing the attacker with the same privileges as the browser process.
OpenCVE Enrichment
Debian DSA