Impact
Use after free in the V8 JavaScript engine allowed a remote attacker to execute arbitrary code inside Chrome's sandbox by delivering a specially crafted HTML page. The flaw is a classic memory management vulnerability, represented by CWE-416 and CWE-825. An attacker can run code with elevated privileges, potentially compromising the system that launched the browser.
Affected Systems
Google Chrome on desktop environments. Versions less than 151.0.7922.72 are vulnerable; the fix was included in the July 2026 stable channel update.
Risk and Exploitability
The overall CVSS score is 8.8, indicating high severity. The EPSS score is below 1%, suggesting that, while capable, exploitation is not widespread yet. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw without authentication by luring a user to a malicious web page, triggering the exploit within the sandbox and potentially breaking out to achieve full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA