Remote attackers could exploit the vulnerability to escape Chrome’s sandbox via crafted HTML pages, potentially achieving code execution on the underlying operating system.
| Vendor | Product | Versions |
|---|---|---|
| chrome | 149.0.7827.53 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cve_cpe | 95% |
| chrome | cert_advisory | 90% | |
| linux | linux_kernel | cve_cpe | 95% |
| microsoft | edge | cert_advisory | 90% |
| microsoft | windows | cve_cpe | 95% |
Updated description with more technical detail, marked exploit as available, and noted that the vulnerability is actively exploited.
Initial creation