Impact
A use‑after‑free flaw present in Google Chrome’s Core rendering engine on Windows allows an attacker who has already compromised the renderer process to escape the browser sandbox. The vulnerability, identified as CWE‑416, could let malicious code gain privileges beyond the renderer, potentially leading to arbitrary code execution on the host. Chromium labels this flaw as high severity.
Affected Systems
Google Chrome for Windows versions prior to 150.0.7871.115 are affected. The issue does not impact other operating systems or Chrome releases newer than the stated version.
Risk and Exploitability
The EPSS score is < 1%, indicating a low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a pre‑existing compromise of the renderer process and delivery of a crafted HTML page. If an attacker can attain the renderer, the bug could be used to escape the sandbox and gain local privilege escalation. No publicly known exploit has been disclosed, so monitoring and prompt patching remain the best approach. The CVSS score of 8.3 indicates a high severity.
OpenCVE Enrichment
Debian DLA
Debian DSA