Impact
This vulnerability arises from a lack of input validation in the AI component of Google Chrome, allowing a malicious HTML payload to exploit the renderer process. When the renderer is compromised, the attacker may escape its sandbox, potentially gaining the ability to execute arbitrary code at a higher privilege level than the browser normally permits. The weakness is classified as CWE‑20 (Input Validation). The official CVSS score is 9.6, indicating a high severity of potential impact on confidentiality, integrity, and availability if exploited. The Chromium security team rated the overall severity as low, but the evidence points to a dangerous escalation path.
Affected Systems
The flaw affects Google Chrome users on all releases prior to version 151.0.7922.72. The affected vendor is Google, product Chrome, and the unpatched versions include any build before the 151.0.7922.72 release announced in July 2026.
Risk and Exploitability
The CVSS score of 9.6 reflects a severe risk, yet the EPSS score of less than 1 % indicates that, so far, real‑world exploitation attempts are extremely rare. The vulnerability is not listed in the CISA KEV catalog. To exploit it, an attacker would first need to supply a carefully crafted HTML page that gets processed by the compromised renderer process, which likely requires either a phishing or social engineering vector to entice the user into loading the malicious page. Once the payload is executed, the renderer can break out of its sandbox and potentially affect the host system.
OpenCVE Enrichment
Debian DLA
Debian DSA