Impact
A use-after-free bug in the Chrome Views component, present before version 150.0.7871.115, can be triggered by a malicious webpage that requires specific user gestures, possibly resulting in heap corruption and allowing an attacker to execute arbitrary code or cause a denial of service. The weakness is classified as CWE-416.
Affected Systems
All Google Chrome desktop installations running a version older than 150.0.7871.115, regardless of channel, are vulnerable.
Risk and Exploitability
The exploit demands a user-interactive trigger, such as a click or scroll, and is not listed in the CISA KEV catalog. With an EPSS score below 1 % and a CVSS score of 7.5, real-world exploitation is unlikely but the potential damage if successful is substantial.
OpenCVE Enrichment
Debian DLA
Debian DSA