Impact
The vulnerability is a use‑after‑free bug in the Input Method Editor of Google Chrome before version 150.0.7871.47. This flaw permits a remote attacker to execute arbitrary code inside the browser’s sandbox when a crafted HTML page is rendered. The official severity rating for Chromium is High.
Affected Systems
All desktop builds of Google Chrome older than 150.0.7871.47, across all operating systems, are affected until the user installs the patched release.
Risk and Exploitability
The CVSS score is 8.8, indicating a high‑severity flaw, while the EPSS score of <1% and absence from CISA’s KEV catalog imply a relatively low exploitation probability at present. The likely attack vector is a or a page that automatically renders in Chrome. Successful exploitation would allow an attacker to run code with the privileges of the current user within the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA