Impact
An internal use after free bug in Chrome's Enterprise code path can corrupt heap objects when a specially crafted HTML document is processed. The flaw may allow a remote attacker to execute arbitrary code on a user’s machine, potentially compromising confidentiality, integrity, or availability.
Affected Systems
All installations of Google Chrome built before 151.0.7922.72 are affected, regardless of operating system. The issue exists in the Enterprise channel and may impact Windows, macOS, and Linux releases that have not yet received the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. An EPSS score of less than 1% suggests that exploitation attempts are currently rare, and the flaw is not listed in CISA's KEV catalog. The likely attack vector, inferred from the description, involves a victim loading a malicious HTML page, so delivery via phishing or compromised websites is most plausible.
OpenCVE Enrichment
Debian DLA
Debian DSA