Impact
An attacker can craft a malicious HTML page that, when rendered by Google Chrome, exploits insufficient validation of untrusted input in the browser’s UI. This flaw is an input validation weakness (CWE‑20, CWE‑1289) and allows a remote attacker who has already compromised the renderer process to escape the browser sandbox. Escaping the sandbox can enable the attacker to execute code on the host with higher privileges, potentially compromising the integrity and confidentiality of the system. The vulnerability is flagged with a high security severity by Chromium.
Affected Systems
Google Chrome versions prior to 151.0.7922.109 are affected. The issue exists in the core browser rendering engine and affects all installations of Google Chrome prior to 151.0.7922.109.
Risk and Exploitability
The CVE description specifies a high severity level, and the EPSS score of < 1 % indicates a very low probability of exploitation, yet the potential impact remains high. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker already manages to supply a crafted HTML payload to a vulnerable renderer instance, suggesting a realistic attack surface through social engineering or malicious web content. Given the high severity and the lack of mitigations in earlier versions, the risk to installations that have not applied the patch remains significant.
OpenCVE Enrichment
Debian DLA
Debian DSA