Impact
The vulnerability is a type confusion error in Chrome’s bindings that enables a remote attacker to execute arbitrary code from a crafted HTML page. This flaw is classified as CWE-843 and grants code execution within the confines of the Chrome sandbox, thereby compromising the confidentiality, integrity, and potentially availability of the user’s data. The impact is high and can be triggered without any need for credentials or local access.
Affected Systems
Google Chrome versions prior to 149.0.7827.103 are affected. The fix is included in the 149.0.7827.103 release and later.
Risk and Exploitability
The exploit requires the victim to view a malicious HTML page, making it a remote, web‑based attack vector. While no EPSS score is available, the vulnerability is listed as high severity (CVSS 8.8) and is not yet in the CISA KEV catalog. Because the flaw allows code to run inside the sandbox, a successful exploit effectively gives the attacker equivalent privilege to the running Chrome instance. The absence of a public workaround means the only reliable mitigation is to apply the vendor’s patch. Users who cannot update are at elevated risk if they encounter malicious web content.
OpenCVE Enrichment