Impact
A use‑after‑free bug (CWE‑416) in Google Chrome’s extension subsystem allows an attacker who persuades a user to install a malicious extension to execute arbitrary code with the privileges of the browser process. The freed object is accessed after its deletion, enabling crafted payloads to trigger execution without further user interaction.
Affected Systems
All desktop releases of Google Chrome prior to version 150.0.7871.47 are affected. Based on the description, it is inferred that the vulnerability remains active as long as the browser’s extension subsystem is enabled.
Risk and Exploitability
The CVSS score of 8.1 indicates a high impact, but the EPSS score of less than 1% suggests that large‑scale exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, meaning no widespread exploits are known, and the likely attack vector involves social engineering to convince a user to install a malicious extension.
OpenCVE Enrichment
Debian DLA
Debian DSA