Impact
The vulnerability arises from a lack of input validation during extension rendering in Google Chrome. A remote attacker who has first compromised the renderer process can present a crafted HTML page that triggers privileged operations, allowing the attacker to elevate privileges within the browser context. Classified as CWE-20, this weakness permits the execution of privileged browser commands, potentially compromising user data or system integrity. With a CVSS base score of 7.5, the flaw represents a medium-level risk for privilege escalation in the renderer process.
Affected Systems
All installations of Google Chrome prior to build 150.0.7871.47, including the stable channel, are vulnerable. The flaw resides in the extensions renderer component; users running a vulnerable build with an extension that processes untrusted input are at risk until the browser is updated.
Risk and Exploitability
Exploitation requires that the attacker first gain control of the renderer process, a non-trivial prerequisite that limits widespread attacks. The EPSS score of <1% and absence from CISA's KEV catalog indicate that documented exploitation is currently unknown. The CVSS score of 7.5 implies that, if exploited, the vulnerability could lead to privilege escalation within the browser but does not directly affect other system components unless the attacker escalates further.
OpenCVE Enrichment
Debian DLA
Debian DSA