Impact
A use‑after‑free flaw in Google Chrome’s core component on Windows allows a maliciously crafted HTML page to trigger a memory corruption bug. The defect can lead to a sandbox escape, giving the attacker execution capabilities beyond the browser process. If the attacker succeeds, arbitrary code could run with the privileges of the user, potentially escalating to full system compromise.
Affected Systems
Google Chrome for Windows versions prior to 150.0.7871.125 are vulnerable. Users of those releases on Windows machines are susceptible and should update to the patched version or later.
Risk and Exploitability
The CVSS score of 9.6 indicates high severity, yet the EPSS score of less than 1% suggests only a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread attacks. The likely attack path is that a remote adversary serves a specially crafted HTML page to a Windows user running an affected Chrome version, potentially enabling sandbox escape and code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA