Impact
The race condition in Chrome’s USB handling, classified as CWE‑362, allows a remote attacker who already has execution a sandbox escape when the browser serves a crafted HTML page. This flaw can elevate code execution beyond the normally restricted browser sandbox, compromising the host system if the renderer is already compromised.
Affected Systems
All Google Chrome installations prior to version 150.0.7871.47 are affected, regardless of operating system.
Risk and Exploitability
The CVSS score of 9.6 indicates high severity. The EPSS score is reported as < 1%, and the vulnerability is not listed in CISA KEV. To exploit the flaw, an attacker must first gain a foothold in the renderer process, which is inferred from the description. Once such a foothold exists, supplying a maliciously crafted HTML document can trigger the race in USB handling, potentially breaking the sandbox and allowing elevated code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA