Impact
The flaw stems from insufficient policy enforcement in the Bluetooth subsystem of Chrome. A crafted HTML page can invoke privileged Bluetooth operations that should normally be forbidden, allowing an attacker to elevate privileges on the local machine. The weakness is categorized as CWE-602, describing improper restriction of access to capabilities that can be abused for privilege escalation.
Affected Systems
Google Chrome versions earlier than 150.0.7871.47 are vulnerable when Bluetooth is enabled and the browser permits access to the API from untrusted origins. The CVE description does not enumerate operating systems, so the impact is limited to any platform where Chrome is installed.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity, yet the EPSS score of less than 1 % indicates a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The probable attack vector involves a malicious web page delivering a custom HTML document that triggers the elevated Bluetooth calls; this inference is drawn from the description because the exact delivery mechanism is not detailed.
OpenCVE Enrichment
Debian DLA
Debian DSA