Impact
Insufficient validation of untrusted input in the extensions module of Google Chrome version 150.0.7871.47 or earlier allows a remote attacker who has compromised the renderer process to perform privilege escalation through a crafted HTML page. The flaw is a CWE‑20 input validation weakness, enabling the renderer to execute privileged operations while rendering malicious content, elevating privileges within the browser context.
Affected Systems
The vulnerability affects all installations of Google Chrome prior to build 150.0.7871.47, including stable channel releases. It resides in the extensions renderer integrated into Chrome; any user running older builds with vulnerable extensions is at risk until the update is applied.
Risk and Exploitability
Based on the description, it is inferred that exploitation requires the attacker to first gain control of the renderer process, a non‑trivial prerequisite that limits the likelihood of widespread attacks. The EPSS score is <1% and, as it is not listed in CISA's KEV catalog, documented exploitation is currently unknown. The CVSS score is 7.5, indicating a medium severity for privilege escalation within the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA