Impact
Use‑after‑free in the Views component of Google Chrome for macOS can cause heap corruption when a specially crafted HTML page is displayed. If the attacker succeeds, arbitrary code could be executed or the browser could crash. The weakness is tied to memory management flaws identified as CWE‑416 and CWE‑787.
Affected Systems
All users running Google Chrome on macOS with a version older than 151.0.7922.72 are affected. The vulnerability has been documented for Chrome prior to this stable‐channel update.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is considered high impact. The EPSS score of less than 1% indicates a very low yet non‑zero likelihood of exploitation in the near term, and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would most likely occur remotely by delivering a crafted webpage that triggers the use‑after‑free. No confirmed exploits are publicly known at this time.
OpenCVE Enrichment
Debian DLA
Debian DSA