Impact
A use‑after‑free flaw was identified in the GPU component of Google Chrome that affects all versions before 151.0.7922.109; the vulnerability is classified as CWE‑416 and CWE‑825. If an attacker succeeds in accessing the freed memory, the flaw permits the renderer process to escape its sandbox, allowing code execution with higher privileges and compromising the confidentiality, integrity, or availability of the affected system.
Affected Systems
The issue applies to any user running Google Chrome older than 151.0.7922.109, regardless of operating system, as the flaw resides within the GPU subsystem present on all platforms. No further sub‑version details are specified beyond the upper bound on the stable release channel.
Risk and Exploitability
The EPSS score is 0.00267 (0.267%), indicating a very low probability of exploitation, while the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 8.3, indicating high severity. An attacker must first compromise the renderer process—likely via a malicious web page—which then can trigger the use‑after‑free through a crafted HTML document. The attack vector is inferred to be a remote interaction over the web, with the potential for sandbox escape if the renderer is compromised.
OpenCVE Enrichment
Debian DLA
Debian DSA