Impact
A use‑after‑free flaw in Google Chrome’s Linux user interface can be triggered by a malicious web page that forces a user to perform specific gestures. The bug allows an attacker to corrupt the browser’s heap and potentially redirect control flow, which can lead to arbitrary code execution. The weakness is identified as CWE‑416 and CWE‑825.
Affected Systems
Google Chrome installations on Linux that are earlier than version 150.0.7871.125 are affected. Any user running a desktop build of Chrome from the stable channel before that release is at risk.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity, yet the EPSS score of less than 1 % suggests that known exploits are rare. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to visit a specially crafted HTML page and perform predetermined UI actions, making it a user‑initiated attack that still demands successful heap corruption for code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA