Impact
Google Chrome’s Headless mode contains a use‑after‑free flaw (CWE‑416). When a malicious HTML page is provided to a Headless instance, the flaw can cause the renderer process to escape its sandbox, potentially allowing the execution of code with higher privileges. The vulnerability can compromise confidentiality, integrity, and availability of the host system. Based on that the attacker must supply a crafted HTML page to a compromised renderer process.
Affected Systems
All Google Chrome releases prior to version 150.0.7871.47 that include a Headless build are affected. Because Headless is a feature of desktop builds, the issue is relevant to the desktop variant of Chrome’s renderer.
Risk and Exploitability
Exploitation requires that an attacker already has control of the renderer process and can supply a crafted HTML page to a Headless instance—an environment that is not typically exposed to untrusted content. The CVSS score is 8.3, indicating high severity, yet the EPSS score is listed as less than 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not present in CISA’s KEV catalog. Based on the description, the likely attack vector is a crafted HTML page delivered to a compromised renderer.
OpenCVE Enrichment
Debian DLA
Debian DSA