Описание
Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
A flaw was found in Google Chrome's USB component. A remote attacker, after compromising the renderer process, could exploit a race condition by using a specially crafted HTML page. This could potentially lead to the execution of arbitrary code outside of the browser's security sandbox, allowing the attacker to gain further control over the system.
Отчет
This Important flaw in the chromium-browser package allows a remote attacker to execute arbitrary code outside the browser's sandbox. Exploitation requires a compromised renderer process and user interaction with a specially crafted HTML page, enabling a significant security bypass.
Дополнительная информация
Статус:
9 Critical
CVSS3
Связанные уязвимости
Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed ...
Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
9 Critical
CVSS3