Impact
An integer overflow (CWE‑472) in the Chromecast component of Google Chrome can be triggered by a crafted HTML page once the renderer process has already been compromised. The overflow corrupts memory, potentially breaking the browser sandbox and allowing the attacker to acquire higher privileges within the browser, indicating that successful exploitation significant loss of confidentiality, integrity, or availability.
Affected Systems
Google Chrome versions prior to 150.0.7871.47 are affected. The specific operating systems that run these versions are not listed in the CVE data, so the earlier claim that all supported operating systems are affected is inferred rather than explicitly documented. Any user running a Chrome release before that version, or any distribution that ships with a Chromium build older than the patched version, is exposed unless the Chromecast component has already been patched or disabled.
Risk and Exploitability
The CVSS score is 8.3, indicating high severity, while the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker first compromise the renderer process; once achieved, a malicious HTML page can trigger the integer overflow to escape the sandbox. Because this flaw exists only in unpatched Chrome releases, the risk is elevated for systems remaining on older versions, but the low EPSS indicates that active exploitation is currently unlikely.
OpenCVE Enrichment
Debian DLA
Debian DSA