Impact
Google Chrome allows a remote attacker who has compromised the renderer process to supply a specially crafted HTML page that can escape the browser sandbox. The weakness is categorized as type confusion (CWE-843).
Affected Systems
Google Chrome browsers on all platforms that use the Dawn rendering engine and are running versions prior to 150.0.7871.47 are affected by this type‑confusion flaw. No other version granularity is currently known.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.6, denoting critical severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The flaw is not listed in CISA KEV. Based on the description, it is inferred that the attacker must control the renderer process, most likely through a malicious HTML page served over the network. Exploitation succeeds if the attacker can manipulate the type system within the Dawn engine to escape the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA