Impact
An integer overflow occurs in the Chromecast component of Google Chrome, affecting all releases prior to 150.0.7871.47, when processing specially crafted HTML content. If an attacker has already compromised the renderer process, the overflow can be triggered and may allow the attacker to escape the browser’s sandbox, potentially gaining higher privileges on the host system. The weakness is classified as CWE‑472.
Affected Systems
Users running Google Chrome versions older than 150.0.7871.47 on any operating system where the Chromecast feature is available are affected.
Risk and Exploitability
The CVSS score of 9.6 indicates a high‑severity vulnerability, while the EPSS score of less than 1% reflects a low observed exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker first compromise the renderer process before the crafted HTML page can trigger the integer overflow and achieve a sandbox escape. This chain makes the risk significant in environments that process untrusted HTML content or have the Chromecast functionality enabled.
OpenCVE Enrichment
Debian DLA
Debian DSA