Impact
A use‑after‑free vulnerability in Google Chrome’s scheduling component can be triggered by a specially crafted HTML page, allowing a remote attacker to execute arbitrary code inside the browser sandbox. The flaw is classified as CWE‑416 and is considered low severity by Chromium security, with a CVSS score of 8.8.
Affected Systems
Google Chrome versions prior to 150.0.7871.47 reside in the core rendering scheduler.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of exploitation. The CVSS score of 8.8 is high numerically, but Chromium security classifies the vulnerability as low severity. Successful exploitation requires a remote attacker to supply a malicious HTML page that Chrome loads, after which arbitrary code can be executed within the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA