Impact
A use‑after‑free flaw in the input handling of Google Chrome allows a remote attacker who has compromised the renderer process to execute a sandbox escape through a crafted HTML page. The escape would grant the attacker privileges of the renderer process, enabling arbitrary code execution with the same rights and potentially allowing full host compromise.
Affected Systems
Google Chrome versions prior to 150.0.7871.186 are vulnerable on all supported platforms. The issue resides in the Chromium renderer component and affects any installation using those legacy versions.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. The EPSS score of <1% points to a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker first compromise the renderer process and then deliver malicious HTML content, making the attack vector a remote content‑based exploitation that leverages a sandbox escape capability.
OpenCVE Enrichment
Debian DLA
Debian DSA