Impact
The vulnerability exists in DevTools of Google Chrome and allows a remote attacker who has already compromised the renderer process to escape the renderer’s sandbox through a crafted HTML page. This flaw originates from an insufficient permission check within DevTools and is classified as CWE‑693, a failure of security controls that permits elevated privileges. Successful exploitation could grant the attacker privileges comparable to or greater than the browser process, enabling arbitrary code execution or privileged actions within the user’s environment.
Affected Systems
Google Chrome desktop versions earlier than 150.0.7871.47 are affected; the issue is independent of operating system, so any supported OS running a desktop build before that revision is susceptible. No server‑side or mobile product is listed.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity, but the EPSS score of <1% shows a very low probability of active exploitation in the wild. The flaw is not listed in CISA KEV, suggesting no publicly known exploit yet. Exploitation requires two steps: first, an attacker must compromise the renderer process via another vulnerability or malicious content; second, the attacker must supply a malicious HTML page that triggers the DevTools escape, so the overall likelihood remains low but non‑zero.
OpenCVE Enrichment
Debian DLA
Debian DSA