Impact
A use‑after‑free bug in Google Chrome’s extension subsystem allows an attacker who persuades a user to install a malicious extension to execute arbitrary code with the privileges of the browser process. The flaw arises when memory previously used by an extension is freed and then accessed, enabling crafted payloads to trigger execution without further user interaction.
Affected Systems
All desktop releases of Google Chrome earlier than version 150.0.7871.47 are affected. Based on the description, it is inferred that the vulnerability remains active as long as the browser’s extension subsystem is enabled.
Risk and Exploitability
The CVSS score of 8.1 indicates a high impact, but the EPSS score is less than 1%, suggesting that large‑scale exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, which means no widespread exploits are known. Based on the description, the likely attack vector is a user installing a malicious extension, possibly through social engineering or deceptive marketing.
OpenCVE Enrichment
Debian DLA
Debian DSA