Impact
An attacker can craft a malicious HTML page that, when rendered by Google Chrome, exploits insufficient validation of untrusted input in the browser’s UI. This flaw is a classic example of input validation weakness (CWE‑20) and allows a remote attacker who has previously compromised the renderer process to escape the browser sandbox. Escaping the sandbox can enable the attacker to execute code on the host with higher privileges, potentially compromising the integrity and confidentiality of the system. The vulnerability is flagged with a high security severity by Chromium.
Affected Systems
Google Chrome versions prior to 151.0.7922.109 are affected. The issue exists in all operating systems where these version ranges are installed, as the flaw resides in the core browser rendering engine.
Risk and Exploitability
The CVE description specifies a high severity level, but no public EPSS score is available. The vulnerability remains unlisted in the CISA KEV catalog. Exploitation requires that the attacker already manages to supply a crafted HTML payload to a vulnerable renderer instance, suggesting a realistic attack surface in social engineering or malicious web content. Given the high severity and the absence of mitigations in earlier versions, the risk to installations that have not applied the patch is significant.
OpenCVE Enrichment