Impact
A use‑after‑free bug in Chrome’s IndexedDB implementation allows a remote attacker to execute arbitrary code inside the browser sandbox by loading a crafted HTML page. The flaw is a memory corruption weakness (CWE‑416). The vulnerability is rated with a CVSS score of 8.8, indicating high severity.
Affected Systems
This issue affects Google Chrome versions prior to 150.0.7871.115 on all operating systems that support IndexedDB. Any machine running one of those versions of Chrome is vulnerable if a malicious web page is displayed in the browser. The bug originates in the Chromium codebase responsible for handling IndexedDB storage and is triggered by an attacker’s crafted HTML content.
Risk and Exploitability
The EPSS score is below 1%, indicating low expected exploitation likelihood. The CVSS score of 8.8 indicates high severity. Attackers must serve a malicious HTML page that a user visits; the exploitation requires user interaction and a network‑based vector. Once the crafted page loads, the use‑after‑free condition can cause arbitrary code to run inside the browser sandbox. The vulnerability is not listed in the CISA KEV catalog. The risk is limited to the sandboxed environment, but could potentially affect data or functionality within the browser context.
OpenCVE Enrichment
Debian DLA
Debian DSA