Impact
The flaw lies in the handling of MHTML files in Google Chrome versions prior to 148.0.7778.96. Through a crafted HTML page, an attacker who has already compromised the renderer process can inject arbitrary scripts or HTML, thereby executing malicious code in the context of the renderer. This cross‑domain injection can lead to the compromise of the user’s data and, depending on the sandbox configuration, potentially further privilege escalation.
Affected Systems
Google Chrome is affected. Any installation using a version older than 148.0.7778.96 is susceptible. The vulnerability is tied specifically to the MHTML handling component of the rendering engine.
Risk and Exploitability
The CVSS score is 5.4, and no EPSS value is available, so the quantitative likelihood is unknown. The vulnerability is not listed in CISA’s KEV catalog, indicating no widely‑known exploits at present. However, the attack requires an initial compromise of the renderer process, meaning the risk is higher for targeted attacks that can achieve in‑process exploitation. The overall risk remains moderate, with the potential impact escalating if sandbox boundaries are breached.
OpenCVE Enrichment
Debian DSA