Impact
This vulnerability is a use‑after‑free flaw in the V8 JavaScript engine that can be triggered by a specially crafted HTML page. When the browser processes the page, uninitialised memory can be accessed, allowing a remote attacker to run arbitrary code within the sandboxed renderer process. The flaw is marked CWE-416 and can lead to code execution with the privileges granted to the browser, potentially enabling further compromise if the sandbox is bypassed.
Affected Systems
All desktop builds of Google Chrome older than version 150.0.7871.46.
Risk and Exploitability
The CVSS score of 8.8 indicates significant exploitability and impact for successful attacks. The EPSS score of less than 1% suggests that observed exploitation in the wild is currently rare. This vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires the victim to render a malicious web page, after which the use‑after‑free can be triggered. Based on the description, it is inferred that the sandbox could be escaped, potentially escalating privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA