Impact
Insufficient validation of untrusted input in Chrome Settings on Windows allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. The flaw stems from improper input handling (CWE‑20) and can lift the attacker’s privileges beyond the isolated renderer, potentially giving control of the Chrome process and the host operating system.
Affected Systems
Google Chrome for Windows users running a Chromium release older than 150.0.7871.47 are affected. The vulnerability targets the renderer sandbox and does not appear to require disabling other security features.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity sandbox escape, while the EPSS score of less than 1% suggests that exploitation is very unlikely under current conditions. The CVE description implies that an attacker must first compromise the renderer process before exploiting the sandbox escape; this is inferred from the wording "remote attacker who had compromised the renderer process". The vulnerability is not listed in CISA’s KEV catalog, indicating no widespread exploitation has been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA