Impact
Google Chrome’s Cast feature contains a flaw that insufficiently validates untrusted input before version 150.0.7871.47. A remote attacker who has already compromised the renderer process can serve a craftily constructed HTML page that triggers escalation of privileges on the host operating system. The vulnerability is an input‑validation weakness (CWE‑20) and is rated with a CVSS base score of 7.5, indicating moderate‑to‑high severity.
Affected Systems
All installations of Google Chrome with versions older than 150.0.7871.47 are impacted. The affected component is the Cast feature in the Chrome browser. Users running version 150.0.7871.47 or newer have the fix applied.
Risk and Exploitability
The EPSS score of less than 1 % suggests a low overall likelihood of exploitation. The CVSS base score is 7.5, indicating moderate‑to‑high severity. The vulnerability is not listed in the CISA KEV catalog, further implying limited current exploitation. Exploitation requires that the attacker already control the renderer process and deliver a malicious HTML page; based on the description, it is inferred that the likely attack vector is web‑based.
OpenCVE Enrichment
Debian DLA
Debian DSA