Impact
A use‑after‑free flaw in the Ozone backend of Google Chrome on Linux allows a remote attacker to reference freed memory by serving a specially crafted HTML page that requires the user to perform specific UI gestures. Successful exploitation results in arbitrary code execution with the privileges of the browser process. The weakness matches CWE‑416 and is rated as high severity by Chromium’s own assessment.
Affected Systems
The vulnerability affects all Google Chrome deployments on Linux running any version prior to 150.0.7871.47.
Risk and Exploitability
The CVSS score of 7.5 indicates a high potential impact. However, the EPSS score falls below 1%, and the flaw is not listed in CISA’s KEV catalog, suggesting an overall low probability of large‑scale exploitation. Exploitation requires the victim to open a malicious HTML document and perform specific UI gestures, so social engineering is a prerequisite. If the conditions are satisfied, the attacker can gain complete control of the browser and potentially the host system.
OpenCVE Enrichment
Debian DLA
Debian DSA