Impact
The vulnerability lies in Google Chrome’s V8 JavaScript engine, where an improper control of privileges (CWE‑693) permits a sandbox escape. A crafted HTML page that requires the victim to perform specific UI gestures can trigger arbitrary code execution within the browser’s sandbox. Based on the description, it is inferred that the attacker must convince the user to carry out these gestures, indicating a social‑engineering component, and that the exploit requires user interaction rather than remote network traffic.
Affected Systems
All installations of Google Chrome running a version older than 150.0.7871.46, regardless of operating system, are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, yet the EPSS score of less than 1% suggests that active exploitation is currently unlikely. Google does not list the issue in its KEV catalog. Exploitation most likely involves a user visiting a malicious webpage and performing the required UI gestures, so remote code injection from external traffic is not possible without user cooperation. Consequently, while the potential impact if exploited is significant, the overall probability of exploitation is low.
OpenCVE Enrichment
Debian DLA
Debian DSA