Impact
A use‑after‑free flaw in the WebMCP component of Google Chrome allows a remote attacker to execute arbitrary code inside a sandbox from a crafted HTML page. The weakness is a classic memory safety issue (CWE‑416). Based on the description, it is inferred that if exploited the attacker can run code with the privileges of the browser process, potentially affecting the host system or other applications running with the same user credentials.
Affected Systems
Google Chrome versions prior to 150.0.7871.186 are affected. The vulnerability exists in all platforms that ship the Chrome browser before this version, including Windows, macOS, Linux, and Chrome OS devices that use the embedded browser component.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity with full remote exploitation ability. The EPSS score of less than 1% indicates a low current likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack can be triggered via a crafted HTML page, meaning any user who opens potentially malicious web content could be compromised. The attack vector is inferred to be a remote attacker delivering a malicious web page to an unsuspecting user who later visits the page in Chrome.
OpenCVE Enrichment
Debian DLA
Debian DSA