Impact
Insufficient validation of untrusted input in the Bluetooth stack of Google Chrome allows an attacker who has compromised the renderer process to craft an HTML page that can trigger a sandbox escape. The vulnerability is linked to CWE-20 (Improper Input Validation) and CWE-1286 (Insufficient Validation of Untrusted Input in Bluetooth). If successfully exploited, the attacker can escape the Chrome sandbox and potentially gain local system access, representing a local privilege escalation scenario.
Affected Systems
Google Chrome desktop versions prior to 151.0.7922.72 on Windows, macOS, and Linux are affected. Versions 151.0.7922.72 and later include the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity. The EPSS score of less than 1% suggests exploitation attempts are rare, and the vulnerability is not listed in the CISA KEV catalog. An attacker must first compromise the renderer process and then serve malicious content via Bluetooth to attempt a sandbox escape. Given the low exploitation probability, the overall risk is moderate but should not be ignored, especially in environments where browsers handle untrusted content or Bluetooth events may be delivered by remote parties.
OpenCVE Enrichment
Debian DLA
Debian DSA