Impact
The vulnerability is a use-after-free flaw in Chrome’s HTML rendering engine. When a crafted HTML page is processed, Chrome may access an object that has already been freed, allowing an attacker to corrupt the heap. The flaw is categorized as CWE-416 and CWE-825 and is reported as high severity by Chromium.
Affected Systems
Affected browsers are Google Chrome versions prior to 151.0.7922.109. All platforms running the stable channel of Chrome before that version are impacted.
Risk and Exploitability
The EPSS score is <1%, and the vulnerability is not listed in CISA’s KEV catalog. Chromium labels it as high severity, suggesting that delivering a malicious HTML page to a Chrome user could result in heap corruption. The likely attack vector is remote via a crafted web page, requiring only victim interaction with Chrome. No information is provided about required privileges or local code execution before the heap corruption occurs. This vulnerability carries a CVSS score of 8.8.
OpenCVE Enrichment
Debian DLA
Debian DSA