Impact
An insufficient enforcement of the extension policy in Google Chrome allows a remote attacker who has already compromised the renderer process to elevate privileges through a crafted HTML page. The flaw enables the attacker to execute code bypassing intended isolation boundaries.
Affected Systems
Google Chrome versions older than 150.0.7871.47 are affected. No official workaround is presently available.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker must first achieve a renderer compromise and then serve a crafted page to further elevate privileges within the browser process.
OpenCVE Enrichment
Debian DLA
Debian DSA