Impact
A use‑after‑free bug in the V8 engine of Google Chrome allows a remote attacker to run arbitrary code that inherits the browser's sandbox privileges. The defect can be triggered by loading a specially crafted HTML page, enabling an attacker to compromise the integrity of the Chromium process and potentially bleed sensitive data that the sandbox context normally protects. The underlying weakness is reflected in CWE‑416 and CWE‑825, indicating memory safety and kernel resource exploitation concerns.
Affected Systems
The flaw exists in Google Chrome versions prior to 151.0.7922.72. Users running any Chrome release older than that build on desktop platforms are affected. The CVE notes the vulnerability in the Chromium project, so any downstream distributions that ship the same code base without the fix are also at risk.
Risk and Exploitability
The CVSS score of 8.8 denotes a high‑severity impact, but the EPSS score of less than 1 % indicates that exploitation is likely rare at this time. The vulnerability is not listed in the CISA KEV catalog, which suggests that no widespread exploitation has been observed publicly yet. Attackers would need to lure a victim into opening a malicious web page or trick the browser into loading the crafted content. Even with a low probability of exploitation, the potential to execute arbitrary code inside the sandbox makes this vulnerability a significant threat for enterprise users and those with elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA