Impact
An integer overflow (CWE-472) in the Chromecast component can be triggered by a crafted HTML page once the renderer process has been compromised. The flaw corrupts memory, giving the attacker the possibility of escaping the sandbox and potentially gaining higher privileges within the browser, which could lead to a loss of confidentiality, integrity or availability.
Affected Systems
All versions of Google Chrome running on any operating system before 150.0.7871.47 are affected. The CVE does not list specific operating systems, so the impact is limited to any system that runs the vulnerable Chrome build. Users who cannot immediately update should be aware that the vulnerability remains if Chromecast remains enabled.
Risk and Exploitability
The vulnerability has a CVSS score of 8.3, indicating high severity. The EPSS score is below 1% and it is not listed in the CISA KEV catalog, implying that active exploitation is currently unlikely. However, once the attacker gains control of the renderer process—a prerequisite for this exploit—they can use a crafted HTML page to trigger the integer overflow and escape the sandbox, elevating their privileges within the browser environment.
OpenCVE Enrichment
Debian DLA
Debian DSA