Impact
The vulnerability is a use‑after‑free flaw (CWE‑416) in Chrome’s Ozone component on Linux. An attacker who has already compromised the renderer process can execute arbitrary code via a crafted HTML page, resulting in a potential sandbox escape. Chromium has rated the issue as high severity.
Affected Systems
Google Chrome on Linux versions prior to 150.0.7871.47 are affected. Linux systems that run a pre‑150.0.7871.47 build and render untrusted web content are potentially vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 9.6, indicating very high severity, and is not yet listed in CISA’s KEV catalog, meaning no known public exploits. The EPSS score of <1% indicates a very low probability of exploitation. Risk remains significant if a renderer process is compromised and a crafted HTML page is loaded, enabling potential sandbox escape and arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA