Impact
A use‑after‑free vulnerability exists in the extension system of Google Chrome that can corrupt heap memory when a malicious extension is installed, potentially allowing an attacker to execute arbitrary code within the browser process. The defect is identified as CWE‑416, a classic memory‑corruption flaw.
Affected Systems
All installations of Google Chrome prior to version 150.0.7871.115 on any supported operating system are affected. Users who load extensions from untrusted or malicious sources are at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates a high potential impact if the flaw is exploited. The EPSS score of less than 1% suggests that the likelihood of exploitation at this time is very low, yet the issue can be leveraged through social engineering by persuading a user to install a compromised extension. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA