Impact
Google Chrome versions prior to 150.0.7871.47 contain an insufficient input validation flaw in the handling of downloaded extensions. The weakness, identified as CWE-20, permits an attacker who successfully convinces a user to install a malicious extension to execute arbitrary code on the user’s machine. Once the code runs, the attacker gains the privileges of the user, compromising confidentiality, integrity, and availability.
Affected Systems
All installations of Google Chrome older than version 150.0.7871.47 on Windows, macOS, and Linux are affected. The flaw applies to every channel—stable, beta, dev, or canary—that has not yet received the update, and to all platforms that run Chrome, as no channel or OS restriction is specified in the advisory.
Risk and Exploitability
The CVSS score of 8.1 classifies the vulnerability as high severity, but the EPSS score of less than 1% indicates a low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. The vulnerability requires user interaction and social engineering to persuade the wearer to install a malicious extension. When the malicious payload is installed, it can be exploited to execute arbitrary code with the user’s privileges, potentially leading to full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA