Impact
A flaw in the Glic component of Google Chrome allows a remote attacker to potentially escape the browser sandbox by insufficient validation of untrusted input (CWE‑20). If exploited, the attacker could gain privileges beyond the sandbox, threatening the confidentiality, integrity, and availability of the host system.
Affected Systems
The issue affects Google Chrome installations before version 150.0.7871.47 on any desktop operating system that runs a vulnerable Chrome instance.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, implying significant impact if the flaw is triggered. The EPSS score of less than 1% suggests that exploitation is rare and not widely observed. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker delivering a malicious web page or untrusted HTML file that the browser renders.
OpenCVE Enrichment
Debian DLA
Debian DSA