Impact
vulnerability is a use‑after‑free (CWE‑416) in the V8 JavaScript engine of Google Chrome prior to version 150.0.7871.46. A maliciously crafted HTML document can trigger heap corruption, and the description indicates that a remote attacker may potentially exploit this to compromise the browser process. The CVSS score of 8.8 reflects the severity of this weakness, and exploitability, but the potential impact remains serious.
Affected Systems
All installations of Google Chrome that run a version older than 150.0.7871.46 are affected by this use‑after‑free flaw.
Risk and Exploitability
The installed EPSS score of less than 1% indicates that the likelihood of public exploitation remains low, and the vulnerability is not featured in CISA’s active exploits. However, the high CVSS score and the description indicating that an attacker must deliver a malicious web page suggest that users are required to interact with compromised content, implying that the attack vector is primarily client‑side via a crafted page. This combination yields a moderate‑high timely patching.
OpenCVE Enrichment
Debian DLA
Debian DSA