Impact
A use‑after‑free flaw in Chrome’s Ozone graphics stack on Linux allows a remote attacker who can entice a user to view a specially crafted HTML page and perform certain UI gestures to corrupt heap memory. If the corruption succeeds, it can result in arbitrary code execution with the privileges of the Chrome process, which is a critical security issue as reflected by the CVSS score of 7.5 and the classification as CWE‑416 and CWE‑825.
Affected Systems
Google Chrome for Linux versions older than 149.0.7827.53 are affected. The vulnerability is confined to the Linux build and does not impact other operating systems.
Risk and Exploitability
The EPSS score indicates an exploitation probability of less than 1 %, suggesting that while the flaw is severe, successful attacks are unlikely under normal conditions. The flaw is not listed in CISA’s KEV catalog. Exploitation requires user interaction with a malicious web page and the execution of specific UI gestures, so it is a client‑side attack vector. If an attacker can meet these conditions, the result could be remote code execution on the victim’s machine.
OpenCVE Enrichment
Debian DSA