Impact
A type confusion flaw in the WebAudio implementation of Google Chrome permits a remote attacker, through a specially crafted HTML page, to execute arbitrary code within the browser’s sandbox. The vulnerability stems from improper type handling in audio processing, classified as CWE‑843, and can be exploited without requiring user interaction beyond visiting the malicious page.
Affected Systems
Google Chrome versions prior to 150.0.7871.182 are affected; all installations that run the vulnerable version on any supported platform are at risk.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity. The EPSS score is below 1%, indicating a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to load a malicious page; it enables an attacker to execute code confined to the browser’s sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA