Impact
This vulnerability is a use‑after‑free (CWE‑416) in the V8 JavaScript engine of Google Chrome versions older than 150.0.7871.46. A maliciously crafted HTML document can trigger heap corruption, potentially allowing a remote attacker to compromise the browser process. The CVSS score of 8.8 indicates that compromise could affect the confidentiality, integrity, and availability of the browsing session. The likely attack vector is client‑side via a malicious web page, as the description explicitly references a crafted HTML document.
Affected Systems
All installations of Google Chrome that run a version older than 150.0.7871.46 are affected by this use‑after‑free flaw.
Risk and Exploitability
The high CVSS score reflects a serious potential impact, but the EPSS score of less than 1% indicates that public exploitation is unlikely. Because the flaw requires a crafted page, the attack vector is limited to client‑side exploitation through a malicious web page. The vulnerability is not listed in the CISA KEV catalog, suggesting that no known active exploits exist at this time. These combined factors point to a moderate but time‑critical risk that diminishes as users upgrade.
OpenCVE Enrichment
Debian DLA
Debian DSA