Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)
Insufficient data validation in the permission request display mechanism (Permission Prompts) allows an attacker to deliver a specially crafted file through a malicious application. Improper input data processing (CWE-20, CWE-138) leads to circumvention of the browser process isolation mechanism (sandbox). The attack requires user interaction — installation of a malicious application.
A successful attack could allow an attacker to escape the browser sandbox, potentially enabling access to the operating system outside the isolated Chrome environment, compromising the confidentiality, integrity, and availability of the system.
Google Chrome should be updated to version 117.0.5938.62 or later. The update is available through the browser's automatic update mechanism and through the official Chrome Stable Channel.
Google Chrome in versions earlier than 117.0.5938.62
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HGoogle Chrome
APPGoogle< 117.0.5938.62
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox