Impact
Google Chrome for Windows before version 150.0.7871.115 contains a flaw in the codecs module that does not properly validate untrusted HTML input. This deficiency enables an attacker, who has already gained code execution inside the renderer process, to escape the browser sandbox and attain privileges higher than the sandboxed process. The vulnerability is mapped to CWE‑20, indicating an input validation weakness. Successful exploitation could allow a malicious actor to execute arbitrary code or perform local privilege escalation on the host system.
Affected Systems
All Windows users running Google Chrome versions earlier than 150.0.7871.115 are vulnerable if the codecs module is enabled. The flaw exists only in the renderer process; other browser processes remain sandboxed.
Risk and Exploitability
The CVSS score of 8.3 classifies this as a high‑risk vulnerability, while the EPSS score of less than 1% indicates that it is rarely exploited in the wild. It is not listed in the CISA KEV catalog. Exploitation requires a prior compromise of the renderer process, followed by the delivery of a crafted HTML page that triggers the flawed validation in the codecs module. The multi‑step nature and prerequisite of renderer compromise reduce the probability of widespread exploitation, though the high severity warrants prompt attention.
OpenCVE Enrichment
Debian DLA
Debian DSA