Impact
This vulnerability arises from insufficient validation of untrusted input in extensions for Google Chrome. A remote attacker who has gained control of the renderer process can feed malformed data from a crafted HTML page, potentially enabling a sandbox escape. The weakness leads to the possibility of executing arbitrary code on the host with at least the privileges of the renderer process, which may be elevated to system-level through the escape path. The primary impact is therefore remote code execution, coupled with a significant breach of the processor’s sandbox isolation.
Affected Systems
Affected system is Google Chrome browsers from versions prior to 151.0.7922.72. The vulnerability is specific to the renderer process handling extensions and manifests in desktop builds of Chrome. All installations of Chrome below this version are exposed and cannot be mitigated by configuration alone.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.8, indicating a medium severity. Its EPSS score is reported as less than 1%, implying a low overall exploitation probability at the time of analysis. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector requires the attacker to compromise the renderer process, which can be achieved via a malicious website or compromised extension. Once control is obtained, the crafted HTML input can trigger the sandbox escape, making exploitation highly feasible for an attacker possessing such foothold.
OpenCVE Enrichment
Debian DLA
Debian DSA