Impact
A use‑after‑free flaw exists in the QUIC networking stack of Google Chrome. When a victim’s browser receives specially crafted QUIC packets, the bug can trigger heap corruption in the browser process. The CVE description states that the vulnerability permits a remote attacker to "potentially exploit heap corruption via malicious network traffic"; it does not specify the precise outcomes of that corruption, so the risk remains that the browser could become unstable or that the memory corruption might be leveraged by an attacker in ways not yet demonstrated.
Affected Systems
All installations of Google Chrome older than version 150.0.7871.47 on any operating system that Chrome supports—Windows, macOS, Linux, and others—may be affected. The CVE record lists only the Chrome product; no additional vendor or product variants are identified.
Risk and Exploitability
The CVSS score of 8.1 reflects a high‑severity defect. The EPSS score is below 1 %, indicating that the probability of widespread exploitation is low at present. The vulnerability is not listed in the CISA KEV catalog. A remote attacker can target the vulnerable browser with crafted QUIC traffic; the attack does not require privileged access or user interaction, though the practical ability to trigger exploitable heap corruption is limited by the complexity of the exploit.
OpenCVE Enrichment
Debian DLA
Debian DSA