Impact
The CVE describes an inappropriate implementation in Chrome’s download handling on Windows that allows a remote attacker to execute arbitrary code by convincing a user to perform specific UI gestures after visiting a crafted HTML page. An input validation issue (CWE‑20) is leveraged, and the flaw depends on the user granting download consent. Chromium rates this as medium severity with a CVSS score of 7.5, indicating a high‑impact vulnerability.
Affected Systems
Google Chrome versions on Windows released prior to 150.0.7871.47 are affected. The fix is included in the stable channel update 150.0.7871.47 and later releases.
Risk and Exploitability
The EPSS score is below 1% and the flaw is not listed in CISA KEV, but the CVSS rating of 7.5 signals that an exploit can lead to full system compromise. Attackers need the victim to interact with a malicious page and perform a minimal UI gesture; once triggered, the flaw allows arbitrary code execution with the browser’s privileges. The low EPSS suggests a limited exploitation risk at present, but the high impact warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA