Impact
An inappropriate DOM implementation in Google Chrome versions prior to 150.0.7871.115 allows a remote attacker to trigger heap corruption by delivering a specially crafted HTML page. The flaw, classified as CWE‑122, can compromise the integrity of memory that the browser manages and may cause crashes or other disruptors of normal browser operation. The official description does not explicitly state that arbitrary code execution is guaranteed, only that heap corruption is possible.
Affected Systems
All installations of Google Chrome running a version older than 150.0.7871.115 are vulnerable. The CVE references the standard Chrome product on all supported platforms, and no OS‑ or distribution‑specific restrictions are mentioned in the data.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity level, while the EPSS score of <1% suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve a client visiting a malicious web site, opening a crafted HTML document, or otherwise rendering unsafe HTML content in an out‑of‑date Chrome instance.
OpenCVE Enrichment
Debian DLA
Debian DSA