Impact
A use-after-free bug in the Views component of Google Chrome allows a remote attacker to cause heap corruption if a user interacts with a specifically crafted web page. This memory corruption could potentially be leveraged to compromise the affected system, including but not limited to crashes or arbitrary code execution under certain conditions. The vulnerability is classified as CWE-416 and CWE-825, indicating a misuse of deallocated memory and a security response weakness.
Affected Systems
The vulnerability affects Google Chrome browsers on all platforms prior to version 151.0.7922.109. Users running any earlier release are vulnerable. No other vendors or products are listed.
Risk and Exploitability
The bug carries a high severity rating of 7.5 and could be triggered by convincing a user to perform certain UI gestures on a malicious web page. Because the attack requires user interaction, the likelihood of exploitation is very low; the EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The vulnerability can be leveraged in targeted phishing or drive‑by scenarios to potentially cause memory corruption and system instability.
OpenCVE Enrichment
Debian DLA
Debian DSA