Описание
Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
A flaw was found in Chromium. A remote attacker, after compromising the renderer process, could exploit insufficient validation of untrusted input in the user interface (UI) by crafting a malicious HTML page. This could potentially allow the attacker to escape the browser's security sandbox, leading to further system compromise.
Отчет
This is an Important vulnerability in Chromium that allows a remote attacker to perform a sandbox escape. While exploitation requires a prior compromise of the renderer process and user interaction with a specially crafted HTML page, a successful attack could lead to significant impact on the system's confidentiality, integrity, and availability. The high attack complexity and user interaction prevent this flaw from being rated Critical.
Дополнительная информация
Статус:
EPSS
8 High
CVSS3
Связанные уязвимости
Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in UI in Google Chrome prio ...
Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
EPSS
8 High
CVSS3