Impact
Insufficient validation of untrusted input in Chrome's printing feature on Windows allows a remote attacker who has already compromised the renderer process to escape the sandbox by serving a crafted HTML page. The flaw lies in improper input validation as indicated by CWE-20 and a broader security weakness, and could lead to privilege escalation or execution of arbitrary code outside the browser sandbox. Chromium rates the issue as low severity, but the potential for sandbox escape warrants attention.
Affected Systems
Google Chrome users running Windows with a Chrome version earlier than 151.0.7922.72 are affected. No other operating systems or versions are explicitly mentioned in the data. The vulnerability is tied to the rendering component, so only Windows builds that include the affected rendering and printing modules are relevant.
Risk and Exploitability
The probability of exploitation is very low, with an EPSS score below 1% and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to compromise the renderer process or bypass the Windows sandbox first, then exploit the unvalidated print input. The mention of low severity by Chromium suggests the impact is limited to users who can influence the renderer. The likely attack vector is inferred to be a two‑stage exploitation: first gaining renderer access, then using the crafted input to escape the sandbox. While exploitation risk is low, the potential for privilege escalation makes patching advisable, especially in environments handling sensitive or untrusted documents.
OpenCVE Enrichment
Debian DLA
Debian DSA