Impact
An integer overflow occurs in the Chromecast component of Google Chrome versions before 150.0.7871.47 when processing specially crafted HTML content. The overflow can only be triggered after a remote attacker has already compromised the renderer process, but it is sufficient to escape the Chromium sandbox and execute code with elevated privileges on the host machine. This weakness is identified as CWE‑472.
Affected Systems
All users running Google Chrome older than 150.0.7871.47 on any operating system where the Chromecast feature is enabled are affected. The problem exists in the stable channel and any in‑house builds that include the Chromecast component without the fix.
Risk and Exploitability
The CVSS score of 9.6 indicates a high‑severity vulnerability, while the EPSS score of less than 1% reflects a low observed exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker first gain control of the Chrome renderer process before the crafted HTML page triggers the integer overflow, which makes the attack chain more complex and limits the likely risk to environments that process untrusted HTML or allow Chromecast usage.
OpenCVE Enrichment
Debian DLA
Debian DSA