Impact
The vulnerability is a use‑after‑free flaw in the Aura component of Google Chrome that permits heap corruption. An attacker can supply a malicious file that, when processed by Chrome, corrupts the heap. The weakness is formally identified as CWE‑416: Use After Free.
Affected Systems
Affected is the Google Chrome browser. Versions prior to 150.0.7871.128 are vulnerable, including all prior stable channel releases. No other Chrome variants or products are explicitly listed as affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact if exploited. The EPSS score of less than 1% shows a very low probability of exploitation in the wild, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector is local: a user who can place a malicious file on the machine and have Chrome parse it – an attacker with local or physical access could aim to trigger the use‑after‑free. No network‑based or remote execution path is described.
OpenCVE Enrichment
Debian DLA
Debian DSA