Impact
A use‑after‑free flaw in Google Chrome’s Input component (CWE‑416) causes a memory management error that lets a remote attacker craft a malicious HTML page to trigger the browser into executing arbitrary code within the sandboxed process. The flaw provides only sandboxed execution and does not necessarily allow escape of the browser environment.
Affected Systems
Google Chrome browsers with revisions earlier than 150.0.7871.115 are vulnerable. All installations running a version older than that snapshot are affected until patched.
Risk and Exploitability
The CVSS score is 8.8, indicating a high impact. The EPSS score is below 1%, suggesting a low likelihood of active exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be a remote crafted HTML page that the victim must open or load over the network, leading to execution within the browser’s sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA