Impact
A flaw in the handling of MHTML files in Google Chrome on macOS allows a remote attacker who has already compromised the renderer process to escape the sandbox and execute code outside the browser’s isolation boundaries. The manipulation of a crafted HTML page triggers this improper implementation, turning what is normally a harmless browser operation into a potential vector for full system compromise. The weakness aligns with CWE-653 and CWE-693, underscoring the lack of sufficient scope constraints and failure to guard against external control of execution paths.
Affected Systems
Users of Google Chrome on macOS running any version prior to 151.0.7922.72 are vulnerable. The issue is confined to the browser’s renderer component and does not affect other operating system components directly, but the sandbox escape permits an attacker to affect the entire user machine once the renderer is breached.
Risk and Exploitability
The CVSS score of 9.6 places this flaw in the high‑severity range, and although the EPSS score is less than 1%, indicating a currently low probability of exploitation, the lack of a KEV listing should not be taken as evidence of inactivity. The attack requires that the attacker already compromise the renderer process, which might be achieved through a separate vulnerability or social engineering. Once executed, the sandbox escape allows full control of the victim’s system, making this a critical threat for any user with unsanitized browsing habits. All three key aspects—score, exploitation probability, and KEV status—combine to suggest that timely remediation is essential.
OpenCVE Enrichment
Debian DLA
Debian DSA