Impact
The vulnerability is insufficient policy enforcement in Chrome’s sandbox on macOS, permitting a renderer process that has already been compromised to craft a malicious HTML page that could escape the sandbox. The weakness involves insufficient policy enforcement (CWE‑653) and is also associated with CWE‑693. If exploited, the attacker would gain the privileges of the compromised renderer process. No additional privilege escalation beyond that process is described in the data.
Affected Systems
Google Chrome browsers for macOS running versions older than 150.0.7871.47 are impacted; newer releases contain the fix announced in the stable‑channel update for the desktop release.
Risk and Exploitability
The CVSS score of 9.6 designates this CVE as Critical. The EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is only exploitable after an attacker has already compromised the renderer process; the sandbox escape then gives them the privileges of that process. The issue is not listed in CISA’s KEV catalog, and no large‑scale exploitation is apparent.
OpenCVE Enrichment
Debian DLA
Debian DSA