Impact
The vulnerability is a boundary‑check failure that allows a remote attacker, who has already taken control of a renderer process, to cause a sandbox escape by loading a specially crafted HTML page. The flaw is mapped to CWE‑20 and provides a path for the attacker to break the isolation boundary surrounding the browser, potentially enabling further actions on the host system.
Affected Systems
All installations of Google Chrome prior to version 150.0.7871.47, on any operating system or device, are potentially impacted. No other vendors or products are implicated by the CNA data.
Risk and Exploitability
The CVSS score of 9.6 indicates a very high risk if the necessary conditions are met, yet the EPSS score of less than 1% and the absence from the CISA KEV catalog suggest that active exploitation is currently unlikely. Successful exploitation requires a pre‑existing compromise of a renderer process followed by delivery of a malicious HTML payload; after the sandbox is breached, the attacker could reach the host operating system and potentially execute arbitrary code.
OpenCVE Enrichment
Debian DLA
Debian DSA