Impact
A use‑after‑free flaw (CWE‑416) in the Chrome user interface allows a crafted web page to trigger heap corruption when a user performs certain UI gestures. This corruption can cause the browser to crash, result in a denial of service, or potentially enable an attacker to execute arbitrary code. The advisory does not confirm that remote code execution is guaranteed, but the presence of heap corruption means that integrity and confidentiality of user data could be at risk if exploitation succeeds.
Affected Systems
Desktop versions of Google Chrome prior to 150.0.7871.182 are affected. The CVE does not specify operating systems, so the platforms impacted are inferred to be the typical supported platforms for Chrome (Windows, macOS, Linux).
Risk and Exploitability
The CVSS score of 8.8 places this issue in the high severity range. An EPSS score of < 1% indicates that current exploitation attempts are unlikely but still possible, especially in targeted or persistent campaigns. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires social engineering: an attacker must persuade a user to visit a malicious web page and then perform the specific UI gestures, pointing to a drive‑by or phishing‑like vector.
OpenCVE Enrichment
Debian DLA
Debian DSA