Impact
This vulnerability is a use‑after‑free flaw in the Ozone backend of Google Chrome that can be triggered by a crafted HTML page, provided the user performs specific UI gestures. The flaw can corrupt heap objects and may allow the attacker to execute arbitrary code on the victim’s system. The weakness is identified as CWE‑416 and CWE‑825, and is rated as Critical by Chromium security. The potential impact is the loss of confidentiality, integrity and availability of the user’s data and the system itself.
Affected Systems
All instances of Google Chrome built before version 150.0.7871.125 are affected, regardless of operating system. The flaw has been reported for the desktop stable channel and applies to all regular user builds. Users should verify that their Chrome version is at least 150.0.7871.125 to ensure the vulnerability is fixed.
Risk and Exploitability
The CVSS score of 7.5 categorises this flaw as high severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV to open a malicious HTML page and perform the required UI gestures, making it a remote, user‑interaction–dependent exploit. If successful, the heap corruption could lead to arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA