Impact
The vulnerability is a use-after-free in the Ozone windowing backend of Google Chrome that exists in releases prior to 150.0.7871.115. A web page created by an attacker could trigger a heap corruption, which may lead to severe integrity or availability compromise, but the CVE description does not guarantee that arbitrary code execution is achieved.
Affected Systems
Google Chrome binary builds released before version 150.0.7871.115 on any platform that employs the Ozone backend are affected. This includes all desktop releases of Chrome and Chromium prior to 150.0.7871.115 across Windows, macOS, Linux and other supported operating systems.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity, while the EPSS score of < 1% suggests a low probability of seeing an attack in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious website that a user visits; opening a crafted page could exploit the heap corruption. Patching mitigates the highest risk.
OpenCVE Enrichment
Debian DLA
Debian DSA