Impact
The vulnerability is a type confusion bug in the Tint layer of Google Chrome prior to version 150.0.7871.46. It allows a remote attacker who can supply the browser to potentially escape the sandbox and execute code outside the browser process. This flaw is identified as CWE-843 and carries a CVSS score of 9.6, indicating severe impact on confidentiality, integrity, and availability.
Affected Systems
All builds of Google Chrome installed before the 150.0.7871.46 update are affected, including the stable channel and any other channels that have not yet applied the fix.
Risk and Exploitability
The attack vector requires that the malicious HTML page be rendered by the browser, which can occur when a user visits a compromised or malicious website or when content is injected into the page. This attack vector is inferred from the description because the vulnerability exploits a crafted HTML page that triggers type confusion in the Tint layer when rendered. The EPSS score is below 1%, indicating a low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Despite the low EPSS, the high CVSS score reflects the risk of privilege escalation if an attacker could successfully escape the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA