Impact
A heap buffer overflow exists in the Chromecast component of Google Chrome versions earlier than 150.0.7871.47. The flaw allows a remote attacker who has already compromised the renderer process to load a specially crafted HTML page that may provoke a sandbox escape, giving the attacker higher privileges within the browser process. The vulnerability does not guarantee control of the underlying operating system and requires an initial renderer-level compromise.
Affected Systems
All installations of Google Chrome on the stable desktop channel running a version earlier than 150.0.7871.47 are susceptible. The issue targets the Chromecast functionality built into the browser, affecting any user who has the Cast feature enabled on those legacy builds.
Risk and Exploitability
The CVSS score of 9.6 marks this flaw as critical, yet its EPSS score is below 1%, indicating a low probability of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation requires an initial renderer compromise, followed by delivery of malicious HTML content. The overall risk depends on how exposed users are to renderer-level attacks and the use of the Cast feature.
OpenCVE Enrichment
Debian DLA
Debian DSA