Impact
Out‑of‑bounds read and write conditions in the Dawn rendering engine of Google Chrome can be triggered by a crafted HTML page. If successfully exploited, an attacker may escape the browser sandbox and run malicious code on the host operating system. The flaw is catalogued as CWE‑125 and CWE‑787 and carries a CVSS score of 9.6, indicating a high severity if exploitation succeeds.
Affected Systems
Google Chrome versions earlier than 150.0.7871.46 are affected. All supported releases that have not yet received the 150.0.7871.46 security update are at risk, so any user running an older build is vulnerable.
Risk and Exploitability
The vulnerability can be exercised remotely by loading malicious HTML content; this is inferred from the description. The EPSS score of < 1% suggests that exploitation is unlikely in current threat markets, yet the CVSS score of 9.6 shows that a successful attack would enable sandbox escape and potentially arbitrary code execution on the host. The issue is not listed in CISA’s KEV catalog, implying no known widely active exploits as of this analysis.
OpenCVE Enrichment
Debian DLA
Debian DSA