Impact
A use‑after‑free flaw in Chrome’s Form handling prior to version 150.0.7871.115 allows a remote attacker to execute arbitrary code by serving a crafted HTML page. The vulnerability is a classic memory corruption bug (CWE‑416), which, once triggered, grants the attacker execution capabilities within the browser’s sandbox. While the sandbox limits system impact, code running in that context can compromise user data, exfiltrate information, or pivot to higher privileges if a sandbox escape or downstream extension is affected.
Affected Systems
All users running Google Chrome stable channel builds older than 150.0.7871.115 are potentially exposed. The exact versions affected are not enumerated in the advisory, but the issue was fixed in the 150.0.7871. is the recommendation for all existing installations.
Risk and Exploitability
The CVE is classified with high severity, yet the EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be through an attacker‑controlled web page that users visit, since the flaw is triggered by a crafted HTML form. Exploitation would require the user to load the exploit page, so the risk is moderate to high actions limited by the browser sandbox, but the impact could still be significant if sandbox escapes or policy violations occur.
OpenCVE Enrichment
Debian DLA
Debian DSA