Impact
A flaw in Chrome’s SanitizerAPI allows a remote attacker to embed malicious scripts or HTML into a crafted page, leading to arbitrary code execution within the browser. This cross‑site scripting weakness (CWE-79) can be used to steal data, hijack sessions, or modify page content, compromising the confidentiality and integrity of the user's browsing session.
Affected Systems
Google’s Chrome browser versions up to and including 148.0.7778.95 are affected. Users should upgrade to 148.0.7778.96 or later to obtain the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, indicating medium severity, and can be triggered by any user who visits a malicious page crafted by an attacker. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. Attackers can exploit it remotely through a standard web request.
OpenCVE Enrichment
Debian DSA