Impact
The vulnerability is a use‑after‑free in the Views component of Google Chrome that can be triggered by a maliciously crafted HTML page. The description states a remote attacker can potentially exploit heap corruption via this page (Chromium security severity: Critical). While the exact outcome of the exploitation is not specified, the potential impact extends to compromised process integrity and confidentiality.
Affected Systems
Google Chrome versions earlier than 150.0.7871.115 on any supported operating system (Windows, macOS, Linux). The issue exists in the stable channel and any prior stable releases before the security update.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of < 1% shows a very low chance of current exploitation, and the vulnerability is not listed in the CISA KEV. An attacker would need to entice a user to load a malicious HTML page or exploit the browser remotely; therefore local user interaction or network-based delivery of the crafted page is required. Given the high CVSS but low EPSS, the overall risk is significant but the likelihood of exploitation remains low at present.
OpenCVE Enrichment
Debian DLA
Debian DSA