Impact
A race condition discovered in Chrome’s GetUserMedia function (CWE-362) allows an attacker who has already compromised the renderer process to trigger a sandbox escape. The vulnerability, quantified with a CVSS score of 8.3, could elevate the attacker’s privileges beyond the confined renderer environment, facilitating further exploitation of the host system.
Affected Systems
Google Chrome browsers running versions older than 150.0.7871.115 are impacted. The updated patch was rolled out in the 150.0.7871.115 release; this statement is inferred from the update notes rather than directly specified in the CVE entry.
Risk and Exploitability
The attack requires the attacker to first gain control of the renderer process and then deliver a crafted HTML page that exploits the race condition. The CVSS score the EPSS score of less than 1% suggests a low probability of exploitation. CISA does not list this vulnerability in its KEV catalog. The sandbox escape potential, however, makes the impact significant if the conditions for exploitation are met.
OpenCVE Enrichment
Debian DLA
Debian DSA