Impact
Google Chrome’s Bluetooth subsystem does not enforce the required policy checks, allowing a maliciously crafted HTML page to trigger privileged Bluetooth actions. The flaw, classified as CWE‑602, can allow an attacker to elevate privileges within the browser, potentially affecting the host operating system. The CVSS score of 8.8 indicates a high severity impact on confidentiality, integrity, and availability of the affected system.
Affected Systems
All desktop installations of Google Chrome older than version 150.0.7871.47—including Windows, macOS, Linux, and ChromeOS—are vulnerable until the user upgrades to the fixed release.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity. The EPSS score of less than 1% suggests that widespread exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker hosting a malicious HTML page that the victim loads into Chrome; because the browser does not enforce Bluetooth policy checks, the page can invoke privileged Bluetooth functions, leading to privilege escalation. The weakness is a violation of policy enforcement as identified by CWE‑602.
OpenCVE Enrichment
Debian DLA
Debian DSA