Impact
A use-after-free vulnerability exists in the Views component of Google Chrome. If a user interacts with a specially crafted web page that requires specific UI gestures, the flaw can trigger heap corruption. The CVSS score of 9.6 indicates critical severity, but the description only cites heap corruption as the consequence.
Affected Systems
Google Chrome desktop releases prior to version 150.0.7871.47 can be exploited when a user of these versions views malicious web content that triggers specific UI gestures.
Risk and Exploitability
The CVSS score of 9.6 signals critical severity, but the EPSS score of < 1% suggests exploitation is currently unlikely. The flaw is not listed in CISA’s KEV catalog. Attackers would need to deliver a maliciously crafted HTML page that forces a user to perform particular UI gestures to trigger the use-after-free. If successful, the resulting heap corruption could destabilize the browser or lead to further exploitation, but the potential for remote code execution is not confirmed in the current description.
OpenCVE Enrichment
Debian DLA
Debian DSA