Impact
A use-after-free condition in the HTML5 Canvas implementation of Google Chrome versions earlier than 150.0.7871.47 allows a remote attacker to execute arbitrary code within the browser's sandbox. The vulnerability is a classic memory‑corruption flaw (CWE-416) that can be triggered by a crafted HTML page code occurs only inside the sandbox.
Affected Systems
All users running Google Chrome prior to version 150.0.7871.47 are affected. The June 2026 update fixed the issue, so the vulnerability is not present in that release. No other vendors or product lines were affected.
Risk and Exploitability
The CVE has a CVSS score of 8.8, indicating a high severity flaw. The EPSS score is less than 1%, suggesting a low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is an attacker hosting a malicious web page that the victim opens or visits; a single click on the page would trigger risk remains moderate to high until a user upgrades to the June 2026 release (version 150.0.7871.47 or later).
OpenCVE Enrichment
Debian DLA
Debian DSA