Impact
The vulnerability arises from insufficient policy enforcement in Chrome’s USB handling, specifically an access control flaw (CWE-693). A remote attacker who has already compromised the renderer process could then serve a crafted HTML page that triggers a sandbox escape, allowing execution of arbitrary code with elevated privileges.
Affected Systems
Google Chrome versions prior to 150.0.7871.47 are affected. Users running earlier releases may be at risk if they access malicious web content that exploits the renderer.
Risk and Exploitability
The CVSS score of 8.3 classifies this finding as high severity. The EPSS score of <1% indicates a low but non‑zero likelihood of real‑world exploitation. The attack vector likely involves delivering a malicious HTML page to a renderer that has already been compromised, triggering the sandbox escape. Because the vulnerability requires both a remote web payload and a prior renderer compromise, the overall risk remains moderate for typical web browsing, but it can lead to remote code execution on the host if exploited.
OpenCVE Enrichment
Debian DLA
Debian DSA