Impact
The vulnerability arises from insufficient policy enforcement in the GPU subsystem of Google Chrome versions prior to 150.0.7871.47. A remote attacker who has already compromised the renderer process can deliver a crafted HTML page that may allow the attacker to escape the renderer sandbox by exploiting the GPU policy flaw. This issue is classified as CWE-693, indicating a failure to enforce security constraints.
Affected Systems
Google Chrome installations running any operating system version earlier than 150.0.7871.47 are affected. The flaw is present in the stable channel and affects all architectures that use GPU acceleration in the renderer process.
Risk and Exploitability
The vulnerability can only be exploited after the attacker first compromises the renderer. Although the attack chain adds complexity, the high CVSS score of 9.6 indicates a severe potential impact if the initial renderer compromise succeeds. The EPSS score of less than 1% suggests a very low probability of in‑the‑wild attacks, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA