Impact
A use‑after‑free flaw (CWE‑416) exists in the Journeys component of Google Chrome. When a renderer process that has already been compromised loads a specially crafted HTML page, the flaw can be triggered, allowing the attacker to escape the renderer’s sandbox and potentially gain higher privileges within the browser environment. The vulnerability carries a CVSS score of 9.6, reflecting a severe threat to the browser’s isolation model.
Affected Systems
The flaw is present in Google Chrome’s Journeys feature on all platforms where the browser is installed. Versions of Chrome released prior to 150.0.7871.47 contain the vulnerability and are therefore affected.
Risk and Exploitability
Exploitation requires that the renderer process has first been compromised, after which a malicious HTML page can trigger the use‑after‑free. The CVSS score of 9.6 indicates substantial risk. The EPSS score is reported as <1 %, suggesting that industrial exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA