Impact
The vulnerability arises from insufficient validation of input data in Chrome’s Codecs component, which can be triggered via a crafted HTML page. This flaw permits a remote adversary to escape Chrome’s sandbox, potentially allowing execution of code outside the browser process or elevation of privileges on the host system. Chromium has classified the issue as high severity.
Affected Systems
All installations of Google Chrome built before version 151.0.7922.109 are affected. The product is Chrome, distributed by Google. Current releases as of the advisory include the fix, but systems that remain on older versions remain vulnerable.
Risk and Exploitability
The CVSS score is not listed, but the advisory labels the problem as high severity. No EPSS data is available, and the vulnerability is not presently tracked in the CISA KEV catalog. An attacker could exploit the weakness by serving the malicious HTML page from a website or embedding it in an email attachment, leveraging the browser’s renderer to trigger the sandbox escape. Successful exploitation would grant code execution outside the confinement of Chrome, potentially leading to full system compromise depending on user privileges.
OpenCVE Enrichment