Impact
Google Chrome versions prior to 150.0.7871.47 contain insufficient enforcement of the WebHID policy, a weakness identified as CWE‑284 (Improper Access Control). The flaw can be exploited when a user installs a malicious or compromised Chrome extension: the crafted extension can abuse WebHID permissions to gain elevated privileges inside the browser context, potentially allowing execution of code beyond its intended scope and compromising the host system.
Affected Systems
All installations of Google Chrome older than 150.0.7871.47 on any supported operating system are vulnerable. The vulnerability can only be triggered when a user installs a malicious or compromised extension, as no automated or remote trigger is available.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of less than 1% suggests a currently low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a socially engineered user installing a malicious extension that abuses the WebHID policy bypass to gain elevated privileges within the browser, potentially affecting the host system.
OpenCVE Enrichment
Debian DLA
Debian DSA