Impact
A use‑after‑free flaw (CWE‑416) in the Forms component of Google Chrome allows a remote attacker to trigger crafted HTML content that results in arbitrary code execution within the browser’s sandbox. The vulnerability can be exercised by opening a malicious HTML page and the impact is elevated execution of code inside the browser process.
Affected Systems
Google Chrome versions earlier than 150.0.7871.47 are affected, and the defect was fixed in Chrome 150.0 releases.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score of < 1% indicates that exploitation is considered rare, but the flaw still permits a remote attacker to trigger arbitrary code execution by opening a crafted HTML page. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment
Debian DLA
Debian DSA