Impact
Google Chrome’s New Tab Page contains insufficient validation of untrusted input. A malicious page crafted by an attacker who has already compromised the renderer process could cause a sandbox escape, allowing execution of arbitrary code or elevation of privileges on the host system.
Affected Systems
The vulnerability affects Google Chrome browsers before version 149.0.7827.103. All users running the affected Chromium‑based stable channel are potentially impacted.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, reflecting significant risk. EPSS data are unavailable, and the weakness is not in the CISA KEV catalog. Attackers would need to deliver a crafted HTML page to the vulnerable New Tab Page and gain control of the renderer process, which could happen through exploitation of another flaw or via social engineering. Once the condition is met, the attacker can escape the renderer sandbox, leading to Remote Code Execution.
OpenCVE Enrichment