Impact
The vulnerability is caused by an inappropriate handling of form data in Google Chrome before version 150.0.7871.115. A maliciously crafted HTML page can trigger the browser to run arbitrary code inside its sandboxed environment. This is a CWE-863 flaw that permits code execution with the privileges of the user’s Chrome process while remaining confined to the sandbox. The impact includes potential compromise of confidentiality, integrity, and availability of data within the browser.
Affected Systems
Google Chrome desktop editions prior to 150.0.7871.115 are affected. The vulnerability exists on all desktop operating systems where Chrome is installed, until the patch is applied.
Risk and Exploitability
Experts infer that the attack requires a user to load a malicious HTML page, making the vector remote and user‑initiated. The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% points to a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploits are known. Nonetheless, because the flaw allows code execution within the browser process, administrators should consider immediate remediation to prevent future exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA