Impact
An uninitialised use vulnerability in Chrome’s accessibility component on Windows allows a remote attacker who has already compromised the renderer process to orchestrate a sandbox escape. The flaw can enable the attacker to break out of the renderer’s restricted environment and execute arbitrary code with higher privileges, posing a severe threat to system integrity and confidentiality.
Affected Systems
Google Chrome on Windows versions prior to 147.0.7727.101 are affected. Users who have not applied the latest patch are at risk.
Risk and Exploitability
The vulnerability is rated high, with a CVSS score of 8.3; the EPSS score is below one percent (< 1%), and it is not listed in the CISA KEV catalog, indicating no current evidence of active exploitation. The attack requires the delivery of a crafted HTML page that successfully compromises the renderer process; once that occurs, the sandbox escape can be achieved. Given the severity, the potential impact is significant if exploitation occurs.
OpenCVE Enrichment
Debian DSA