Impact
The flaw is due to an insecure implementation in Chrome's password handling component, exposing a heap corruption vulnerability that can be triggered by a crafted web page. An attacker could send a malicious HTML document to a user’s browser, causing a remote participant’s memory to be corrupted and potentially leading to a crash, denial of service, or alteration of execution flow. This issue is classified as CWE-20, indicating improper input validation of user‑supplied data.
Affected Systems
All releases of Google Chrome older than version 150.0.7871.47 are affected. The vulnerability resides in the password management subsystem. The advisory does not provide explicit platform coverage; therefore, we cannot confirm which specific operating systems are impacted, but the impact could extend to any platform where Chrome is installed.
Risk and Exploitability
The CVSS score of 8.8 reflects the high potential impact if exploited. The EPSS score is less than 1%, indicating a very low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker convincing a user to visit a malicious page, which then triggers the heap corruption. Consequently, while the exploitation risk remains moderate due to the low EPSS, the severity warrants timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA