Impact
A use‑after‑free flaw in Google Chrome’s GPU component allows a remote attacker who has already compromised the renderer process to load a crafted HTML page that triggers the renderer to free memory and then access it again. This defect, classified as CWE‑416, can enable the attacker to escape Chrome’s sandbox and execute privileged code on the host, presenting a critical security risk.
Affected Systems
Versions of Google Chrome prior to 150.0.7871.47 that use GPU‑accelerated rendering are affected.
Risk and Exploitability
The CVSS score of 9.6 signals a highly impactful sandbox escape. The EPSS score of < 1 % indicates a very low likelihood of exploitation at the time of reporting, and the vulnerability is not listed in CISA’s KEV catalog so no publicly known exploits exist yet. Based on the description, the attacker already has compromised the renderer process; delivering a crafted HTML page that triggers the use‑after‑free enables sandbox escape.
OpenCVE Enrichment
Debian DLA
Debian DSA