Impact
An integer overflow bug in the Chromecast component of Google Chrome can be triggered by malicious network traffic originating from the local system. When a local attacker crafts specific data, the overflow allows the attacker to escape the browser sandbox, potentially gaining elevated privileges to execute arbitrary code with system‑level access. The vulnerability indicates that erroneous arithmetic operations can corrupt memory and lead to control‑flow hijack, allowing the attacker to read, modify or execute files outside the browser’s restricted environment.
Affected Systems
The flaw appears in Google Chrome for desktop before version 150.0.7871.182. Any desktop operating system that supports Chrome (Windows, macOS, Linux) is affected, provided the user runs a version older than the specified release. The vulnerability is local, meaning it requires the attacker to run code on the same machine or have the capability to send packets processed by Chrome.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability that this vulnerability will be exploited. The vulnerability is not listed in the CISA KEV catalog. However, the CVSS‑derived severity of High makes the impact substantial if exploited. The attack vector is inferred to be local, involving a crafted network packet, because the bug is in the Chromecast network handling code. An attacker with local code execution rights could therefore exploit the overflow to escape the sandbox and execute arbitrary code. Due to the low exploitation likelihood, monitoring is advisable, but the high impact warrants immediate remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA