Impact
Insufficient policy enforcement in Chrome's Linux sandbox allows a remote attacker to craft a malicious HTML page that may lead to a sandbox escape. The likely attack vector is that a victim opens such a page, for example via phishing or social engineering. If the escape succeeds, the attacker could execute code with the privileges of the browser process, potentially compromising system integrity. The specific assets or actions available after the escape are not explicitly defined in the provided data.
Affected Systems
Google Chrome running on Linux systems using the stable channel is affected if the version is older than 149.0.7827.53. All Linux distributions that install Chrome from the regular release channel before this update are vulnerable.
Risk and Exploitability
The CVSS score of 9.6 classifies this vulnerability as critical. The EPSS score is reported as less than 1%, indicating a very low but nonzero exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The likely exploitation path is that a remote attacker serves a crafted HTML page that a victim opens, possibly via phishing. If the attacker successfully escapes the sandbox, they could execute code with the browser process’s privileges, potentially escalating privileges and compromising the system. These exploitation details are inferred from the description and standard sandbox escape behaviors.
OpenCVE Enrichment
Debian DSA