Impact
Google Chrome’s Bluetooth component lacks proper policy enforcement, enabling an attacker to craft an HTML page that triggers privileged Bluetooth operations without authorization. This is a CWE‑602 weakness that results in privilege escalation within the browser and can potentially affect the underlying operating system.
Affected Systems
All desktop installations of Google Chrome older than version 150.0.7871.47—including Windows, macOS, Linux, and ChromeOS—are vulnerable until the user upgrades to the fixed release.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity. The EPSS score of less than 1% suggests that widespread exploitation is presently unlikely. The flaw is not listed in the CISA KEV catalog. Likely attack path involves the attacker hosting a malicious HTML page that the victim loads into Chrome; because the browser does not enforce Bluetooth policy checks, the page can invoke privileged Bluetooth functions, leading to privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA