Context-Inappropriate Capability
High
- Confidence
- 97% confidence
- Finding
- The script launches Chrome with --no-sandbox while rendering attacker-controlled Markdown-derived HTML. Because rendered Markdown may include active HTML elements or resource references, any browser compromise during rendering would execute without Chrome's normal sandbox isolation, increasing the chance of local code execution or file/system access under the user's privileges.
