Impact
An integer overflow in the Chrome Extensions API allows an attacker, who has convinced a user to install a malicious extension, to read memory outside the intended bounds. The vulnerability is identified as CWE‑190 and can lead to data leakage from the victim’s browser process. The official severity is high in Chromium’s internal ranking.
Affected Systems
All desktop installations of Google Chrome with a version number lower than 150.0.7871.115 are affected. The flaw exists in the extensions handling code across all common platforms (Windows, macOS, Linux). Any installed extension that accesses the vulnerable API is capable of triggering the overflow.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity. The EPSS score is lower than 1%, evidencing that exploitation probability is low. The vulnerability is not listed in CISA’s KEV catalog. The attack requires a user to install a malicious extension, which limits the vector to social engineering. Nonetheless, once in place, the extension can perform out‑of‑bounds reads that could expose application‑level data.
OpenCVE Enrichment
Debian DLA
Debian DSA