Impact
A use‑after‑free bug in Google Chrome Extensions allows a remote attacker to execute arbitrary code inside the browser’s sandbox by delivering a specially crafted HTML page. The flaw is identified as CWE‑416 and delivers code‑execution privileges limited to the sandbox, but still capable of compromising browser data and potentially allowing further attacks. It is likely that the attack vector involves delivering a malicious HTML document that, when opened in Chrome by a user with the vulnerable extension installed, triggers the use‑after‑free. The description suggests that the vulnerability can be exploited without user interaction beyond opening the malicious page; this inference is drawn from the wording and may require the presence of the vulnerable extension.
Affected Systems
Versions of Google Chrome earlier than 150.0.7871.47 are affected. If the user has not upgraded to the patched version, the browser’s extension system can be triggered by loading a malicious HTML document.
Risk and Exploitability
Based on the description, the likely attack vector is that an attacker crafts a malicious HTML page and delivers it to a user with the vulnerable extension installed, which triggers the use‑after‑free and remote code execution within the browser’s sandbox. The CVSS score of 8.8 reflects high severity, while the EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV. Although the sandbox limits escalation to the browser process, remote code execution within the sandbox remains a serious threat to browser data and the user’s environment.
OpenCVE Enrichment
Debian DLA
Debian DSA