Impact
Chrome on ChromeOS contains a CameraCapture component that fails to constrain the bounds of untrusted data. A maliciously crafted HTML page can trigger an out‑of‑bounds memory read, allowing an attacker to read arbitrary data from the browser’s address space. The flaw is classified as CWE‑125, provides read‑only access, and does not grant execution privileges. The CVSS score of 9.8 indicates a critical impact on confidentiality.
Affected Systems
All versions of Google Chrome on ChromeOS prior to 150.0.7871.47 are affected. Devices running those older browser releases are vulnerable regardless of user profile or usage patterns.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog and the EPSS score is below 1 %, indicating a very low probability of widespread exploitation. The likely attack vector is remote via a crafted web page that the user visits or which is injected into the browser; this inference comes from the description of an out‑of‑bounds read triggered by web content. With a CVSS of 9.8, the potential for a serious confidentiality breach remains high, underscoring the need for timely patching.
OpenCVE Enrichment
Debian DLA
Debian DSA