Impact
Chrome on Linux contains a use‑after‑free bug in the Views rendering component that can be triggered by a crafted HTML page. The flaw allows a remote attacker to corrupt the heap and potentially execute arbitrary code, compromising the confidentiality, integrity, and availability of the affected user’s data. The weakness is classified as CWE‑416.
Affected Systems
The vulnerability affects Google Chrome on Linux distributions running any version older than 151.0.7922.72. Users of the stable channel prior to the 151.0.7922.72 update are impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity exploit, though the EPSS score of less than 1% suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to serve a malicious web page to the victim, implying an untrusted content vector, and could potentially achieve arbitrary code execution on the victim’s system.
OpenCVE Enrichment
Debian DLA
Debian DSA