Impact
Based on the description, heap-based buffer overflow (CWE-20) and heap corruption in the WebNN component of Google Chrome on Windows. It requires that an attacker have already compromised the renderer process before. With access to the renderer, an attacker can serve a crafted HTML page that exploits the overflow, causing heap corruption and potentially compromising the integrity of the renderer. The flaw stems from improper input validation, which allows malformed input to overwrite a buffer on the heap.
Affected Systems
The flaw impacts users of Google Chrome prior to version 150.0.7871.47 in which the WebNN API is enabled. Systems that have updated to 150.0.7871.47 or newer are not susceptible. It is inferred that users on other operating systems or browsers are not affected, as the vulnerability description only mentions Windows and Chrome; however this is not explicitly stated.
Risk and Exploitability
Based on the description, it is inferred that the attacker must first gain control of the renderer process, a prerequisite that limits the vulnerability to scenarios where the renderer has already been compromised. The likely attack vector involves delivering a crafted HTML page after taking over the renderer. The CVSS score of 8.8 indicates high severity, yet the EPSS score of less than 1 % and absence from the KEV list suggest that widespread exploitation is unlikely at present. Consequently, the overall risk remains moderate, contingent on the presence of a prior compromise or malicious content path that reaches the renderer.
OpenCVE Enrichment
Debian DLA
Debian DSA