Impact
A use‑after‑free flaw exists in the Network component of Google Chrome. A maliciously crafted HTML page can trigger a heap corruption, potentially allowing an attacker to execute arbitrary code. This flaw is classified as CWE‑416 and is rated as critical by Chromium security.
Affected Systems
Google Chrome versions prior to 150.0.7871.128 on the stable desktop channel are affected. Users running these older releases are susceptible to the use‑after‑free during page rendering.
Risk and Exploitability
The most likely attack vector is a crafted HTML page served by an attacker that the victim opens. The CVSS score of 9.6 reflects a high severity level, but the EPSS score of < 1 % suggests that exploitation remains uncommon at present. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation at the time of this analysis.
OpenCVE Enrichment
Debian DLA
Debian DSA