Impact
An integer overflow in the Dawn rendering engine of Google Chrome on Windows – identified as CWE-472 – allows a remote attacker to craft an HTML page that may trigger a sandbox escape. The vulnerability, classified as Medium severity by Chromium, could let a malicious webpage bypass Chromium’s sandbox isolation and gain elevated privileges on the host system. The impact is primarily the potential elevation of privileges for an attacker executing code from a vulnerable Chrome instance.
Affected Systems
The flaw exists in Google Chrome on the Windows platform for all releases prior to version 148.0.7778.96. Any user running one of those versions remains at risk unless updated to a patched release.
Risk and Exploitability
The attack vector appears to be remote via a specially crafted HTML page that a user could load. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the current exploitation likelihood is uncertain, but the potential for sandbox escape represents a high impact if exploited. The CVSS score of 8.8 denotes a high severity rating, indicating significant risk to confidentiality and integrity on systems where the affected Chrome version runs unrestricted web content.
OpenCVE Enrichment
Debian DSA