Impact
A heap buffer overflow exists in the WebNN component of Google Chrome on Windows versions prior to 150.0.7871.47 when the renderer process is already compromised. The flaw is caused by improper input validation (CWE‑20) and unchecked buffer bounds, allowing a crafted HTML page to overwrite adjacent heap memory. Overwriting heap memory can corrupt internal data structures of the renderer, potentially giving an attacker the ability to alter the execution flow or read/write protected data, although the description does not confirm full remote code execution.
Affected Systems
All users of Google Chrome running Windows with the WebNN API enabled on a Chrome version older than 150.0.7871.47 are affected. The vulnerability is specific to the Windows platform; no other operating systems or browsers are mentioned in the vendor statement.
Risk and Exploitability
With a CVSS score of 8.8 this issue is rated high severity, but the EPSS score of less than 1 % and current absence from the CISA KEV catalog suggest that widespread exploitation is unlikely. Exploitation requires that the renderer has already been taken over and that the attacker can supply a malicious HTML document; these prerequisites limit real‑world risk to scenarios where local or remote content can be injected into the browser. The overall built‑in defenses make direct exploitation difficult, but if the conditions are met the impact could be severe.
OpenCVE Enrichment
Debian DLA
Debian DSA