Impact
A use‑after‑free flaw in Chrome’s Autofill component allows an attacker to execute code inside the browser’s sandbox. The vulnerability stems from improper memory handling (CWE‑416), resulting in the ability to run arbitrary code when a malicious HTML page is viewed. The flaw can bypass the normal browser security model and may compromise the underlying operating system if an exception occurs.
Affected Systems
Google Chrome versions earlier than 151.0.7922.72 are affected. The issue exists in the stable channel of the desktop browser on all supported platforms. Newer releases contain the patch that removes the use‑after‑free condition.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity. The EPSS score is below 1%, indicating a low probability of widespread exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The attacker would need to lure a user to a crafted HTML page that triggers the flaw, which can be delivered via phishing or compromise of a trusted site. Once triggered, the attacker gains sandboxed code execution and could potentially escape the sandbox with a second compromise step.
OpenCVE Enrichment
Debian DLA
Debian DSA