Impact
Afree flaw in the V8 JavaScript engine employed by Google Chrome allows a remote attacker to craft a malicious HTML page that, when a user performs specific UI gestures, causes the browser to read freed memory and execute arbitrary code inside the sandbox. The issue is identified as CWE‑416 and is judged high severity by Chromium’s security team.
Affected Systems
The affected product is Google Chrome. All builds prior to version 150.0. the vulnerability is triggered when the user visits a crafted web page that induces the required gesture interactions.
Risk and Exploitability
The flaw can be exploited remotely by delivering a tailored web page. While exploitation requires user interaction, social engineering can make this feasible. The CVSS score is 7.5, the EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Organizations should consider the risk significant if users are exposed to malicious sites containing the flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA