Impact
Insufficient validation of untrusted input in Chrome’s user interface allows a remote attacker to craft a malicious HTML page that can escape the browser sandbox and potentially execute arbitrary code. The flaw represents an input validation weakness (CWE‑20, CWE‑1286) and could compromise the confidentiality, integrity, or availability of the underlying operating system if exploited.
Affected Systems
Google Chrome versions older than 149.0.7827.103 on any supported platform are vulnerable. All installations that have not applied the recent update from the Chrome stable channel are at risk.
Risk and Exploitability
Chromium assigns this issue a high security severity, with a CVSS score of 9.6, placing it in the Critical range. The EPSS score is <1% (0.0009), indicating a very low yet non-zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Because the exploit requires delivery of a crafted HTML page, the attack vector is likely remote via a network channel (e.g., the user visiting a malicious site). The lack of a public exploit and a critical severity level suggest a significant risk if the vulnerability remains unpatched.
OpenCVE Enrichment
Debian DSA