Impact
Use‑after‑free in the Dawn rendering engine in Google Chrome versions before 151.0.7922.72 allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The flaw arises when the browser accesses freed memory after a rendering operation, which can lead to arbitrary code execution within the confined sandbox of the browser process.
Affected Systems
Google Chrome users running any version earlier than 151.0.7922.72 on the stable channel are affected. The vulnerability appears in the Dawn component of the browser and applies to all platforms that run the stable channel of Chrome.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity issue that can compromise the integrity of the browsing sandbox. However, the EPSS score is reported as less than 1%, suggesting that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a malicious or compromised web page that is rendered by the browser, leading to remote code execution in the sandboxed environment.
OpenCVE Enrichment
Debian DLA
Debian DSA