Impact
Google Chrome versions prior to 150.0.7871.47 contain an insufficient validation flaw in the handling of downloaded extensions. The weakness, identified as CWE-20, allows an attacker who successfully convinces a user to install a malicious extension to execute arbitrary code on the user’s machine. Once the code runs, the attacker gains full control of the system, compromising confidentiality, integrity, and availability.
Affected Systems
All installations of Google Chrome prior to version 150.0.7871.47 are affected. The description does not specify particular channels or operating systems, so the flaw applies to every channel that has not yet received the update and to all platforms that run Chrome.
Risk and Exploitability
The flaw requires user interaction and social engineering to persuade the user to install a malicious extension, so the exploitation probability is low, reflected by an EPSS score of less than 1% and the absence from CISA’s KEV catalog. However, the CVSS score of 8.1 classifies it as high severity. Once the malicious extension is installed, the vulnerability can be leveraged to execute arbitrary code with the privileges of the user, exposing the system to full compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA