Impact
Insufficient policy enforcement in Chrome's compositing subsystem allows an attacker who has already compromised the renderer process to execute arbitrary code inside the browser's sandbox. The flaw is triggered by a crafted HTML page, giving the attacker control over sandboxed code paths.
Affected Systems
Google Chrome browsers prior to version 149.0.7827.53 are affected. The vulnerability exists in all platforms where the compositor runs – Windows, macOS, Linux and Chrome OS – and applies to every user who may load arbitrary or malicious web content.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. While the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the requirement for the renderer to already be compromised means an attacker needs a foothold in the renderer. If the renderer can be executed with elevated privileges by local or remote code, the flaw can be leveraged to escape the sandbox and execute code with the privileges of the user context.
OpenCVE Enrichment