Impact
A use‑after‑free flaw exists in Chrome’s Views component that can be triggered when a remote attacker serves a crafted HTML page and holds the user to perform specific UI gestures. The vulnerability is classified as CWE‑416 and can cause corruption of the browser heap, which may result in application instability, a crash or other adverse effects, but the description does not confirm code execution as a guaranteed outcome.
Affected Systems
All Google Chrome releases older than 150.0.7871.47 on any operating system are affected. Users operating a build before this version on any platform are at risk whenever they visit a malicious web page that contains the exploit.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity. An EPSS of <1% suggests exploitation is rare in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a remote attacker hosting a malicious site and the user completing a series of UI gestures, making the attack vector remote and interactive.
OpenCVE Enrichment
Debian DLA
Debian DSA