Impact
A use after free vulnerability in V8 allows an attacker who convinces a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. This can lead to arbitrary code execution as indicated by CWE‑416 and CWE‑825.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 are vulnerable. The flaw exists in the V8 JavaScript engine used by the browser.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score of < 1% shows a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Likely attack requires an attacker to persuade a user to install a malicious extension, which then exploits the use after free to run code within the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA