Impact
A crafted HTML page can trigger a flaw in Google Chrome’s Enterprise implementation, allowing an attacker to execute arbitrary code. The vulnerability is classified as CWE‑94, meaning an unsafe code execution issue. The attacker could run code with the privileges of the browser process, potentially escalating to system compromise.
Affected Systems
The flaw affects any installation of Google Chrome with a version earlier than 151.0.7922.72, regardless of operating system, because the issue resides in the core rendering engine.
Risk and Exploitability
The CVSS score of 8.8 marks this as a high‑severity weakness. The EPSS score of less than 1% indicates that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, it can be triggered remotely through a specially crafted web page and does not require any user interaction. Until the vendor releases a patch, the risk remains significant for systems that have not upgraded.
OpenCVE Enrichment
Debian DLA
Debian DSA