Impact
A use‑after‑free flaw in the Chrome installer on Windows allows a local attacker that supplies a malicious installer file to execute arbitrary code with the privileges of the installing user. The vulnerability carries a CVSS score of 7.8 and is classified as a use‑after‑free (CWE‑416).
Affected Systems
All Windows installations of Google Chrome earlier than 150.0.7871.47 are affected. The issue is limited to the Windows operating system; other platforms are not impacted. Installing or updating to Chrome 150.0.7871.47 or a later release removes the use‑after‑free condition.
Risk and Exploitability
The EPSS score is < 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. However, because the flaw permits local privilege escalation, any user who can run a crafted installer file poses a risk. The CVSS score of 7.8 warrants immediate patching.
OpenCVE Enrichment
Debian DLA
Debian DSA