Impact
The vulnerability is a use‑after‑free condition in Chrome’s DNS component that allows a malicious renderer process to exploit an uninitialized pointer, leading to a sandbox escape and execution of code with the browser process’s privileges. The flaw is classified as CWE‑416 and CWE‑825, indicating an improper release of resources and the unexpected use of a freed object.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 are affected. The flaw exists in all builds where the DNS resolver runs in the renderer process, meaning any installation that has not applied the latest stable update carries the risk.
Risk and Exploitability
The CVSS score of 9.6 signals critical severity, but the EPSS score of <1 % indicates a very low probability of exploitation in the wild. The vulnerability requires an attacker to gain control of the renderer process—typically via malicious web content—and then serve a crafted HTML page that triggers the use‑after‑free. Successful exploitation would grant arbitrary code execution on the host system. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA