Impact
A use‑after‑free defect in the Views component of Google Chrome, found in versions prior to 150.0.7871.115, can be triggered by a malicious webpage that requires specific user gestures, potentially producing heap corruption that may lead to arbitrary code execution or denial of service. The flaw is classified as CWE‑416.
Affected Systems
All installations of Google Chrome older than 150.0.7871.115, regardless of channel (stable, beta, dev), are vulnerable. The issue appears in desktop builds and is removed in Chrome 150.0.7871.115 and later releases.
Risk and Exploitability
The vulnerability demands a user-interactive trigger, such as a click or scroll, prompted by a crafted HTML page. Because the EPSS score is below 1 % and the flaw is not listed in the CISA KEV catalog, in-the-wild exploitation chances are low, yet the CVSS score of 7.5 indicates substantial potential damage if an attacker succeeds.
OpenCVE Enrichment
Debian DLA
Debian DSA