Insufficient policy enforcement in developer tools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html | release notes vendor advisory |
https://crbug.com/1342722 | issue tracking exploit vendor advisory |