Impact
Use after free in Ozone when Chrome on Linux processes a crafted HTML page that requires the user to engage in specific UI gestures, which can corrupt heap memory and potentially allow an attacker to execute arbitrary code. This is a CWE-416 vulnerability. Chromium classified the flaw as high severity.
Affected Systems
Google Chrome on Linux, via the Ozone graphics stack, is vulnerable in all releases before 150.0.7871.128. The flaw impacts every Linux installation that uses the Ozone backend, including stable channel builds.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity, but the EPSS score of <1% indicates a low current exploitation probability. The vulnerability requires a user to open a crafted web page and perform UI actions, limiting immediate attacks but still presenting serious risk. It is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA