Impact
A use-after-free flaw was discovered in Google Chrome's DevTools component before release 150.0.7871.47. The bug can be triggered by a maliciously crafted HTML page, causing the browser to execute arbitrary code within its sandboxed environment. The description notes that the code runs inside the browser process; there is no explicit evidence of sandbox escape, so the impact remains confined to the Chrome process. This vulnerability is a use‑after‑free (CWE‑416) flaw.
Affected Systems
All Google Chrome installations built before version 150.0.7871.47 are affected. The vulnerability exists across all supported operating systems and build types, including desktop builds that incorporate the same DevTools code base.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity flaw, while the EPSS of < 1% points to a very low probability of exploitation in the near future. The vulnerability is not listed in the CISA KEV catalog. The only information available about delivery is that the flaw resides in DevTools and can be triggered via a crafted HTML page; it is inferred that the attacker must have the victim open Chrome DevTools, which is not user‑friendly but allows the malicious code to run inside the browser process.
OpenCVE Enrichment
Debian DLA
Debian DSA