Impact
A use-after-free flaw in the Chrome renderer allows a dangling pointer to be dereferenced after the memory block has been freed. When triggered by a specially crafted HTML page, this flaw can escape the renderer sandbox and grant the attacker the ability to execute code with system privileges. The weakness is formally identified as CWE-416 and carries a CVSS score of 9.6, indicating critical severity.
Affected Systems
The vulnerability affects Google Chrome versions prior to 150.0.7871.47 on all supported operating systems. Users running those earlier stable releases are exposed if the renderer component contains the unpatched code. The vendor's advisory implies the issue is limited to the stable channel on desktop, but this inference is not directly supported by the payload.
Risk and Exploitability
The EPSS score of < 1% suggests that while exploitation is currently unlikely, the high CVSS rating of 9.6 means serious damage can result if the flaw is exploited. The flaw requires that the attacker already has control over the renderer process, which typically implies a preceding compromise or malicious content. Although it is not listed in CISA's KEV catalog, the combination of critical severity and the potential for remote code execution warrants immediate attention.
OpenCVE Enrichment
Debian DLA
Debian DSA