Impact
The flaw is a use‑the InterestGroups component of Google Chrome. An attacker can craft a malicious HTML page that triggers the freed memory access, allowing arbitrary code execution inside the browser’s sandbox with the privileges of that process.
Affected Systems
Based on the description, it is inferred that Google Chrome browsers prior to version 150.0.7871.115 are affected across all operating systems supported by Chrome—Windows, macOS, Linux, and Chrome OS—because the same Chromium code path is used on each platform.
Risk and Exploitability
The CVSS score of 8.8 indicates a high impact on confidentiality, integrity, and availability. The EPSS score of less than 1% indicates a very low exploitation probability in the wild, and it is not listed in the KEV catalog. Exploitation requires a user to visit a maliciously crafted web page; it is inferred that the attack vector is the web content channel. Once triggered, the attacker gains sandboxed code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA