Impact
The flaw in Google Chrome is a heap corruption vulnerability caused by an inappropriate XML parsing implementation prior to version 150.0.7871.47. When the browser parses a specially crafted HTML page that includes maliciously constructed XML content, memory on the heap can be corrupted, potentially allowing a remote attacker to affect the stability or behavior of the browser. The description indicates a high severity rating but does not state that arbitrary code execution is guaranteed, so the worst‑case impact is limited to corruption of browser state.
Affected Systems
Google Chrome versions older than 150.0.7871.47 are affected. The vulnerability originates in the browser’s XML parser and is triggered when the browser loads an HTML page that contains a maliciously constructed XML payload, typically served from a compromised or malicious website.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is highly severe, yet the extremely low EPSS score conditions. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits have been reported. The most plausible attack scenario involves a malicious or compromised site delivering the crafted HTML page to a victim’s browser, but a successful exploit remains uncertain due to the lack of confirmed exploitation evidence.
OpenCVE Enrichment
Debian DLA
Debian DSA