Impact
This vulnerability is an out‑of‑bounds read bug in the Dawn rendering engine of Google Chrome. When a specially crafted HTML page is processed, the engine accesses memory beyond the intended buffer, potentially allowing a remote attacker to escape the browser’s sandbox and execute code with elevated privileges. The flaw is classified as CWE‑125 and carries a CVSS score of 9.6, indicating a high severity potential though Chromium rates the internal severity as low.
Affected Systems
Google Chrome for desktop is affected. Any Chrome release prior to version 150.0.7871.46 is vulnerable; users running older stable channel builds are at risk.
Risk and Exploitability
The flaw requires delivery of a crafted HTML page to the vulnerable browser, which is a straightforward out‑of‑band attacker scenario. Although the EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, the possibility of sandbox escape grants local code execution. This serious impact necessitates timely remediation, even if exploit activity remains limited.
OpenCVE Enrichment
Debian DLA
Debian DSA