Impact
The CVE arises from a use‑after‑free bug in the Ozone graphical backend of Google Chrome. When a crafted HTML page is rendered, the attacker can trigger the freed memory usage to escape the browser's sandbox and potentially execute arbitrary code on the host system. This is a critical flaw, rated CVSS 9.6, that can compromise confidentiality, integrity, and availability if exploited.
Affected Systems
The vulnerability affects Google Chrome for desktop operating systems. All versions released prior to 151.0.7922.72 are susceptible. Users running Chrome in stable channel mode that have not applied the 151.0.7922.72 update or later are at risk.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low but non‑zero probability of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a maliciously crafted HTML page opened in Chrome, where the attacker relies on the renderer process to trigger the sandbox escape. Because the flaw involves memory corruption, exploitation requires delivery of the crafted content and a Chrome instance that loads it, which is common in normal browsing scenarios. The high CVSS score reflects the severity of potential remote code execution if the sandbox is bypassed.
OpenCVE Enrichment
Debian DLA
Debian DSA