Impact
A use‑after‑free flaw in Blink allows an attacker to cause execution of arbitrary code while the browser is still under sandbox protection. The flaw is activated by a specially crafted HTML document delivered from a remote source. If exploit succeeds, the attacker can run code within the browser process with elevated privileges, potentially compromising the host system.
Affected Systems
Google Chrome versions earlier than 150.0.7871.186 are vulnerable. Any user running the affected build on a desktop platform may be impacted.
Risk and Exploitability
The issue carries a CVSS score of 8.8, indicating high severity. Its EPSS score is below 1%, suggesting a low probability of widespread exploitation at present, and it is not listed in CISA’s KEV catalog. The likely attack path involves a remote attacker hosting a malicious HTML page that a victim’s Chrome browser will load, hence baseline protection is user level or network filtering.
OpenCVE Enrichment
Debian DLA
Debian DSA