Insufficient data validation in InterestGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 148.0.7778.96 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cve_cpe | 95% |
| chrome | cert_advisory | 90% | |
| linux | linux_kernel | cve_cpe | 95% |
| microsoft | windows | cve_cpe | 95% |
Updated vendor to Microsoft, added product Edge, and marked exploit availability and active exploitation as true.
Updated severity to CRITICAL, noted no exploit available, and corrected the patch version to 147.0.7727.138.
Initial creation