Impact
A use‑after‑free vulnerability in Core in Google Chrome prior to 150.0.7871.47 could let an attacker who has compromised the renderer process escape the sandbox and run code with higher privileges on the host. The flaw allows the attacker to pass crafted HTML that triggers the vulnerability, enabling execution of arbitrary code and leading to loss of confidentiality, integrity, and availability on the compromised system.
Affected Systems
All installations of Google Chrome older than update 150.0.7871.47 are vulnerable. The issue is believed to target the Stable channel, as inferred from release notes, and is confined to the core codebase; newer versions are not affected.
Risk and Exploitability
Chromium rates the vulnerability as Medium. The CVSS score of 9.6 indicates a high severity. The EPSS score is less than 1%, showing a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. Exploitation requires a pre‑existing compromise of the renderer process and the delivery of malicious HTML content, which limits the attack surface. Nonetheless, the high potential impact warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA