Impact
Google Chrome suffered a vulnerability input that was insufficiently validated within its WebRTC component. A maliciously crafted HTML page could exploit this flaw and allow an attacker to execute code with the privileges of the host system. This flaw is classified as CWE‑20. Although Chromium labels it as low severity, privilege escalation threatens both confidentiality and integrity of the affected machine.
Affected Systems
The flaw affects Google Chrome versions prior to 150.0.7871.47 on desktop platforms. Any system running an insecure version and capable of rendering tabbed web content is at risk.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 8.8, indicating high severity. The likely attack vector is remote via a crafted HTML page, inferred from the vulnerability description that it involves a maliciously crafted HTML page. Privilege escalation could be achieved without user interaction beyond opening the malicious page. Because the flaw resides in a widely used browser, the likelihood that such a page could be accessed by unsuspecting users is non‑negligible, an inference derived from Chrome’s ubiquity, warranting timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA