Impact
Insufficient validation of untrusted input in the WebAppInstalls component of Google Chrome allowed a remote attacker to execute arbitrary code inside Chrome's sandbox via a crafted HTML page. This weakness, identified as CWE‑20 Input Validation, enables malicious code execution. Based on the description, it is inferred that no special credentials or system access beyond visiting the vulnerable page are required.
Affected Systems
All desktop users running a Chrome build older than version 150.0.7871.47 are affected. The vulnerability is specific to the WebAppInstalls feature and does not impact other Chrome modules.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity, yet the EPSS score of < 1% indicates a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers would need to deliver a malicious HTML page targeting the vulnerable WebAppInstalls feature; based on the description, the likely attack vector is such a page. The impact is confined to the sandboxed Chrome environment but still constitutes arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA