Impact
Uninitialized use in the Dawn rendering engine of Google Chrome creates a potential heap corruption flaw. A crafted HTML page can trigger the bug, which allows a remote attacker to corrupt memory while the page is processed. This memory corruption could lead to arbitrary code execution or a denial‑of‑service condition within the browser context.
Affected Systems
All releases of Google Chrome prior to version 150.0.7871.47 are vulnerable. Versions 150.0.7871.47 and later contain the fix.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. The EPSS score is below 1 %, indicating a low likelihood of exploitation in the wild. This vulnerability is not listed in CISA’s KEV catalog. The advisory describes exploitation via a malicious web page, implying that the attack can be performed remotely without requiring local privileges. However, the lack of explicit privilege requirements is inferred from the described attack scenario and not explicitly stated in the official disclosure.
OpenCVE Enrichment
Debian DLA
Debian DSA