Impact
The flaw in Google Chrome is a heap corruption vulnerability caused by an inappropriate XML parsing implementation in versions prior to 150.0.7871.47. When the browser parses a specially crafted HTML page, memory on the heap can be corrupted, potentially allowing a remote attacker to affect the stability or behavior of the browser. The official description indicates a high severity rating but does not state that arbitrary code execution is guaranteed, so the worst‑case impact is limited to corruption of browser state.
Affected Systems
Chrome versions older than 150.0.7871.47 are affected. The vulnerability originates in the browser’s XML parser and is triggered when the browser loads an HTML page that contains a maliciously constructed XML payload, typically served from a compromised or malicious website.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is highly severe, yet the extremely low EPSS score (<1%) indicates that exploitation is unlikely under normal conditions. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits have been reported. The most plausible attack scenario involves a malicious or compromised site delivering the crafted HTML page to a victim’s browser, but the exact impact of a successful exploit remains uncertain due to the lack of confirmed exploitation evidence.
OpenCVE Enrichment
Debian DLA
Debian DSA