Impact
The vulnerability is a use‑after‑free bug in the Dawn rendering engine in Google Chrome. A crafted HTML page can cause the browser to free an object while it is still referenced, allowing an attacker to escape the renderer sandbox and potentially execute code outside the browser. This flaw is rated as CWE‑416, indicating a memory safety issue that can lead to arbitrary code execution.
Affected Systems
The issue affects desktop versions of Google Chrome on the stable channel that are older than 150.0.7871.46. Based on the description, it is inferred that users on Windows, macOS, or Linux who have not upgraded to this or newer releases are at risk. The rendering engine behavior is identical across platforms, so the impact is uniform regardless of OS.
Risk and Exploitability
The CVSS score of 9.6 reflects a high severity remote exploit potential. The EPSS score is below 1%, suggesting that the likelihood of exploitation remains low at the time of analysis, though the existence of a critical flaw in a widely used browser warrants attention. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the most probable attack vector is a maliciously crafted HTML page that the user opens, which could be delivered remotely or via local phishing. The exploitation would provide an attacker with sandbox escape, potentially leading to full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA