Impact
Insufficient validation of untrusted input in Contextual Tasks allows a remote attacker to generate a crafted HTML page that can elevate privileges on the affected system. This flaw is both an input validation weakness (CWE‑20) and a Web‑based content injection flaw (CWE‑79), enabling an attacker to run code with higher privileges than the process normally has, potentially compromising the infected machine.
Affected Systems
All users of Google Chrome who have not upgraded to version 151.0.7922.109 or later are affected. The exact affected versions prior to the patch are not listed, so any earlier releases are likely vulnerable.
Risk and Exploitability
With a CVSS score of 8.8, the flaw is considered high severity. The EPSS score is < 1% and the description does not mention an existing exploit, so it is inferred that no publicly disclosed exploit is known. Because the vulnerability is triggered by a malicious HTML page, the attacker must entice a user to visit the page, implying user interaction is required. The flaw is not listed in CISA’s KEV catalog, but the high CVSS score and the privilege escalation capability make patching a priority.
OpenCVE Enrichment
Debian DLA
Debian DSA