Impact
A use-after-free vulnerability occurring in the Ozone component of Google Chrome on Linux can corrupt the heap when a user performs specific UI gestures in response to a crafted HTML page. This flaw, classified as CWE-416 and involving improper handling of dynamic data (CWE-825), enables a remote attacker who convinces a user to engage in those gestures to potentially exploit heap corruption, which could lead to serious compromise of the affected system but does not necessarily imply execution of arbitrary code.
Affected Systems
Google Chrome running on Linux systems with a version earlier than 150.0.7871.125 is affected. No other platforms or products are listed as impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5 and an EPSS score of less than 1%, indicating a high severity but a currently low probability of exploitation. It is not listed in the CISA KEV catalog. To exploit the flaw, a remote attacker must convince a user to perform certain UI gestures after loading a malicious HTML page, which is inferred from the description of the required user actions.
OpenCVE Enrichment
Debian DLA
Debian DSA