Impact
A use‑after‑free vulnerability in Google Chrome’s Document Object Model can be triggered by a crafted HTML page that a remote attacker controls, allowing the attacker to execute arbitrary code inside the browser’s sandbox. The flaw is a classic memory corruption bug (CWE‑416) that grants the attacker the privileges of the browser process without requiring additional user interaction. If exploited, the attacker gains the ability to run arbitrary code on a victim’s machine with the same privileges as the user running Chrome, potentially leading to full system compromise.
Affected Systems
All Chrome releases older than 150.0.7871.47 are impacted. The vulnerability exists in the desktop stable channel, and any user running one of these earlier builds is at risk.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The flaw is not catalogued in CISA’s KEV inventory. Exploitation requires the attacker to deliver a malicious web page or file that the victim opens in Chrome; no special network exploits or elevated privileges are needed.
OpenCVE Enrichment
Debian DLA
Debian DSA