Impact
Chromium’s Chromecast integration in Google Chrome lacks proper policy enforcement, allowing a remote attacker to cause privilege escalation through a specially crafted HTML page. The flaw permits the attacker to bypass expected access controls within the Chrome process, potentially executing code that runs with higher privileges than the typical browser context. Based on the description, it is inferred that a malicious HTML file can be delivered to a victim who opens the page in Chrome, thereby triggering the exploit.
Affected Systems
All users running Google Chrome versions earlier than 150.0.7871.47 are affected. The vulnerability resides in the Chromecast component of Chrome, so any installation of Chrome on Windows, macOS, or Linux that includes Chromecast support is vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity for the flaw. The EPSS score of < 1% shows that the likelihood of exploitation in the wild is very low, and it is not listed in the CISA KEV catalog. Nonetheless, the attack requires a victim to open a crafted HTML page in Chrome, which is a plausible scenario for phishing or drive‑by‑download attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA