Impact
The vulnerability is a use‑after‑free flaw in the WebRTC implementation of Google Chrome. A maliciously crafted HTML page can cause the browser to use memory that has already been freed, allowing an attacker to execute arbitrary code within Chrome’s sandboxed process. This flaw falls under CWE‑416. The primary impact is remote code execution, which could compromise the integrity of the victim’s device and enable further malicious activity.
Affected Systems
All installations of Google Chrome with versions earlier than 150.0.7871.115 are affected. This includes stable channel builds released in 2026 across Windows, macOS, Linux, and Android. Users or organizations that have not upgraded beyond this version remain vulnerable to exploitation via a crafted HTML page.
Risk and Exploitability
Chrome’s team assigned a CVSS score of 8.8, indicating high severity. The EPSS score is below 1%, suggesting a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits at this time. Based on the description, it is inferred that the attack vector requires delivery of a crafted HTML page, typically accessed via HTTP or HTTPS, which triggers the use‑after‑free within the WebRTC code path.
OpenCVE Enrichment
Debian DLA
Debian DSA