Impact
A use‑after‑free vulnerability exists in the Actor component of Google Chrome. The flaw allows a remote attacker to write code that runs inside the browser’s sandbox when a user loads a malicious HTML page. The CVE description does not state that code can escape the sandbox or that additional privileges are obtained.
Affected Systems
All versions of Google Chrome prior to 150.0.7871.115 are.
Risk and Exploitability
The vulnerability can be triggered remotely by loading a malicious HTML document; no additional interaction is required beyond visiting the page. Any user who loads such a page is at risk of executing arbitrary code within the browser sandbox. A CVSS score of 8.8 indicates high severity. The EPSS score of less than 1% suggests it is not listed in the CISA KEV catalog, but defenders should still consider the high severity and apply the available patch promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA