Impact
Google Chrome’s New Tab Page does not adequately validate untrusted input. A malicious page that a remote attacker can load into the vulnerable renderer process could cause the sandbox to be escaped, enabling execution of arbitrary code or elevation of privileges on the host system.
Affected Systems
The vulnerability affects Google Chrome browsers prior to version 149.0.7827.103. All users running the affected Chromium‑based stable channel are potentially impacted. The affected operating systems are Windows, macOS, and Linux as indicated by the CPE list.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. The EPSS score is < 1%, and the weakness is not listed in the CISA known‑exploited catalog. Attackers would need to deliver a crafted HTML page to the vulnerable New Tab Page and already have compromised the renderer process. Once these conditions are met, the attacker can escape the renderer sandbox, leading to Remote Code Execution.
OpenCVE Enrichment
Debian DSA