Impact
A use‑after‑free condition in Google Chrome's HTML5 Canvas implementation, present in versions earlier than 150.0.7871.47, allows a remote attacker to execute arbitrary code within the browser sandbox through a crafted HTML page. This memory‑corruption flaw (CWE‑416) exploits a freed memory reference and can be triggered without user interaction beyond opening the malicious page.
Affected Systems
All users running Google Chrome prior to version 150.0.7871.47 are affected. The June 2026 stable channel update that shipped version 150.0.7871.47 or later includes the patch, eliminating the issue. No other vendors or product lines were impacted.
Risk and Exploitability
The CVE has a CVSS score of 8.8, indicating high severity, while its EPSS score is less than 1 %, suggesting a low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is a malicious web page that the victim visits, where a single click or page load can trigger the use‑after‑free path and execute code within the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA