Impact
Insufficient policy enforcement in the Serial API of Google Chrome before version 150.0.7871.47 allows a remote attacker, who has already compromised the renderer process, to escape the sandbox and potentially execute arbitrary code. The flaw involves improper input validation (CWE‑20) and inadequate permission checks (CWE‑602).
Affected Systems
All users running Chrome Desktop Stable on any operating system before Chrome 150.0.7871.47 are affected. The vulnerability is specific to Chrome’s Serial API implementation and is not present in later releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.6, indicating high severity, but the EPSS score of less than 1% suggests a low probability of exploitation under current conditions. It is not listed in the CISA KEV catalog. The likely attack vector requires the attacker to first compromise the renderer process, for example via malicious web content or compromised network traffic, and then exploit the Serial API sandbox escape to gain code execution privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA