Impact
The vulnerability is a use‑after‑free in the Views component of Google Chrome that can be triggered by a maliciously crafted HTML page. When the browser processes such a page, a memory object is freed and later accessed, leading to heap corruption. While the description indicates the possibility of remote exploitation, it does not specify the exact outcome, so the impact is limited to the potential for compromised process integrity and confidentiality.
Affected Systems
Google Chrome versions earlier than 150.0.7871.115 on any supported operating system (Windows, macOS, Linux). The issue exists in the stable channel and any prior stable releases before the security update.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of < 1% shows a very low chance of current exploitation, and the vulnerability is not listed in the CISA KEV. An attacker would need to entice a user to load a malicious HTML page or exploit the browser remotely; therefore local user interaction or network-based delivery of the crafted page is required. Given the high CVSS but low EPSS, the overall risk is significant but the likelihood of exploitation remains low at present.
OpenCVE Enrichment
Debian DLA
Debian DSA