Impact
A use‑after‑free vulnerability occurring in the Ozone component of Google Chrome on Linux can corrupt the heap when a user performs specific UI gestures in response to a crafted HTML page. This flaw, classified as CWE‑416, enables a remote attacker who convinces a user to engage in those gestures to potentially execute arbitrary code, thereby taking full control of the affected system.
Affected Systems
Google Chrome running on Linux systems with a version earlier than 150.0.7871.125 is affected. No other platforms or products are listed as impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5 and an EPSS score of less than 1 %, indicating a high severity but a currently low probability of exploitation. It is not listed in the CISA KEV catalog. To exploit the flaw, a remote attacker must convince a user to perform certain UI gestures after loading a malicious HTML page, which is inferred from the description of the required user actions.
OpenCVE Enrichment
Debian DLA
Debian DSA