Описание
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
A flaw was found in Google Chrome's CrashReporting component. A heap buffer overflow vulnerability allows a remote attacker, who has already compromised the renderer process, to potentially escape the browser's security sandbox by crafting a malicious HTML page. This could lead to further compromise of the user's system.
Отчет
This Important vulnerability in Chromium's CrashReporting component allows a remote attacker to perform a sandbox escape. After an initial compromise of the renderer process, typically through user interaction with a crafted HTML page, a heap buffer overflow can be exploited to bypass the browser's security sandbox. This is considered Important due to the potential for further system compromise once the sandbox is breached, despite the prerequisite of an already compromised renderer.
Дополнительная информация
Статус:
8.3 High
CVSS3
Связанные уязвимости
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0 ...
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
8.3 High
CVSS3