Impact
The flaw is a use‑after‑free bug in Google Chrome’s Input Method Editor that allows a malicious web page to trigger arbitrary code execution inside Chrome’s sandbox. Exploitation relies on rendering a crafted HTML document and exploits memory corruption to read or write data during the parsing of that page. The vulnerability is rated high severity by Chromium due to its ability to elevate privileges within the browser process.
Affected Systems
All Google Chrome installations earlier than version 150.0.7871.47, regardless of operating system, are vulnerable until the user updates to the patched release.
Risk and Exploitability
With a CVSS score of 8.8, the issue is considered high severity, while an EPSS score of less than 1% and absence from CISA’s KEV catalog suggest a low likelihood of current exploitation. The attack vector is a crafted web page that automatically loads in Chrome, allowing an attacker to run code with the same privileges as the user within the browser’s sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA