Impact
The vulnerability arises from insufficient enforcement of WebHID policy rules in Google Chrome versions prior to 150.0.7871.47, making it a CWE‑284 flaw. An attacker can craft a malicious Chrome extension that misuses WebHID permissions to gain elevated privileges within the browser context, potentially allowing the attacker to execute code beyond the intended scope of the extension and affect the host system.
Affected Systems
All installations of Google Chrome older than 150.0.7871.47 on any supported operating system are vulnerable. The flaw can only be exploited when a user installs a malicious or compromised extension; it cannot be triggered without user interaction.
Risk and Exploitability
The CVSS score of 8.1 reflects high severity, while an EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves socially engineered user installation of a malicious extension that abuses the WebHID policy bypass to gain elevated privileges within the browser and potentially affect the host system.
OpenCVE Enrichment
Debian DLA
Debian DSA