Impact
Google Chrome’s Chromoting component on Linux contains a use‑after‑free flaw that allows an attacker to execute arbitrary code by sending specially crafted network traffic. The vulnerability arises from using memory after it has been freed, enabling malicious control over the execution flow once the component processes the received data. An attacker can run code with the privileges of the Chrome process, potentially compromising the entire system. This flaw is categorized as CWE‑416.
Affected Systems
Users running Google Chrome on Linux with a version earlier than 150.0.7871.47 are affected. The Chromoting component provides Chrome Remote Desktop functionality and is present in the main browser package.
Risk and Exploitability
The CVSS score of 9.8 indicates high severity, but the EPSS score of < 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, implying no widespread public exploitation. Attackers would likely deliver malicious traffic that mimics legitimate remote‑desktop data, a remote network‑based vector that requires no local user interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA