Impact
Improper input validation in the processing of themes allows a remote attacker who has already compromised the renderer process to potentially execute arbitrary code inside the renderer’s sandbox via crafted network traffic. The flaw arises from insufficient sanitization of theme data, enabling code execution with the sandboxed renderer’s privileges. Based on the description, it is inferred that the attacker’s capabilities are limited to the sandbox and the option to escape to the host system is not explicitly documented.
Affected Systems
Google Chrome desktop releases before version 154.0.8037.57 are affected, as indicated in the CVE data.
Risk and Exploitability
The CVSS score of 8.3 categorises this vulnerability as high severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker to have already gained control of the renderer process, which typically involves a sophisticated threat actor. Based on the description, it is inferred that the attacker can run code inside the sandbox but there is no evidence of a full system compromise.
OpenCVE Enrichment
Debian DSA