Impact
Chromium’s Chromecast integration in Google Chrome lacks proper policy enforcement, allowing a remote attacker to perform privilege escalation by delivering a specially crafted HTML page. The flaw enables the attacker to bypass the expected access controls within the Chrome process, potentially executing code that runs with higher privileges than the normal browser context. Based on the description, it is inferred that the attacker must create and persuade the victim to open the malicious HTML page in Chrome, triggering the exploit.
Affected Systems
Google Chrome versions earlier than 150.0.7871.47 on all platforms where Chrome includes Chromecast support (Windows, macOS, Linux).
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of < 1 % shows that the likelihood of exploitation in the wild is very low, and the vulnerability is not listed in CISA KEV. The attack requires the victim to open a crafted HTML page in Chrome, which is a plausible scenario for phishing or drive‑by‑download attacks. The likely attack vector is remote delivery of a malicious HTML file, and it is inferred that the attacker would need the victim to enable or view the Chromecast feature in the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA