Impact
The Chrome Bluetooth subsystem enforces insufficient policy, allowing a crafted web page to invoke privileged Bluetooth operations. An attacker can elevate local privileges by exploiting this flaw, which is identified as a privilege escalation weakness (CWE‑602).
Affected Systems
All installations of Google Chrome versions older than 150.0.7871.47 that have Bluetooth enabled and permit API access from untrusted origins are vulnerable. The vulnerability applies to any platform running the affected browser version, as no operating‑system restriction is mentioned.
Risk and Exploitability
The CVSS score of 8.8 signals high severity, yet the EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, implying limited exploitation likelihood at present. Inferred attack vectors include a malicious web page that serves a custom HTML document capable of triggering the elevated Bluetooth calls, due to the description’s mention of a crafted HTML page.
OpenCVE Enrichment
Debian DLA
Debian DSA