Impact
The vulnerability is an insufficient validation of untrusted input in the Chromoting component of Google Chrome on Windows. When a user can supply a specially crafted file that is processed by Chromoting, the flaw allows the attacker to execute code with the privileges of the current user, effectively elevating local privileges on the machine. This flaw falls under CWE-20, an input‑validation weakness.
Affected Systems
Google Chrome for Windows versions earlier than 150.0.7871.47 are affected. Only the Windows build of Chrome is impacted; no other operating systems or products are listed.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the exploitation vector is inferred to be local because the description states a malicious file must be dropped and a running Chrome instance is required. The EPSS score of < 1% signals that the likelihood of real-world exploitation is very low. Since the vulnerability is not listed in the CISA KEV catalog, no documented exploit campaigns are known, but a local attacker who can create or place the malicious file can readily achieve privilege escalation if the patch is not applied.
OpenCVE Enrichment
Debian DLA
Debian DSA