Impact
An uninitialised use vulnerability in Chrome’s accessibility component on Windows allows a remote attacker who has already compromised the renderer process to orchestrate a sandbox escape. The flaw can enable the attacker to break out of the renderer’s restricted environment and execute arbitrary code with higher privileges, posing a severe threat to system integrity and confidentiality.
Affected Systems
Google Chrome on Windows versions before 147.0.7727.101 are affected. Users of this browser edition who have not applied the latest patch are at risk.
Risk and Exploitability
The vulnerability is rated high, with a CVSS score of 8.3; however, the EPSS score is not available and it is not listed in the CISA KEV catalog, indicating no current evidence of active exploitation. The attack requires the attacker to deliver a crafted HTML page that successfully compromises the renderer process; once that is achieved, the sandbox escape can occur. Given the severity, the potential impact is significant if exploitation occurs.
OpenCVE Enrichment