Impact
The vulnerability lies in Google Chrome’s V8 JavaScript engine, where an improper control of privileges (CWE‑693) permits a remote attacker who convinces a user to perform specific UI gestures to execute arbitrary code within the browser’s sandbox. Based on the description, it is inferred that the attacker must convince the user to carry out these gestures, indicating a social‑engineering component, and that the exploit requires user interaction rather than remote network traffic.
Affected Systems
All installations of Google Chrome running a version older than 150.0.7871.46, regardless of operating system, are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, yet the EPSS score of < 1% further suggests that active exploitation is currently unlikely. Google does not list the issue in its KEV catalog. Exploitation most likely involves a user visiting a malicious web page and performing the required UI gestures, so remote code injection from external traffic is not possible without user cooperation. Consequently, while the potential impact if exploited is significant, the overall probability of exploitation remains low.
OpenCVE Enrichment
Debian DLA
Debian DSA