Impact
A use‑after‑free vulnerability was discovered in the Aura graphics subsystem of Google Chrome on Linux. The flaw can be triggered by a crafted HTML page, allowing a remote attacker to potentially escape the browser sandbox and execute code with the same privileges as the browsing user. The weakness is categorized as CWE‑416, which indicates a freed memory access misuse with serious integrity and availability implications.
Affected Systems
All installations of Google Chrome running versions prior to 151.0.7922.109 on Linux are affected. The vulnerability was identified in the Aura subsystem, which is used by all modern Chrome builds on this platform.
Risk and Exploitability
The vulnerability has a critical severity rating from Chromium’s internal scoring system and could lead to full system compromise if exploited. No EPSS score is available, so the likelihood of exploitation is unknown, and the flaw is not listed in the CISA KEV catalog. Attackers would need to host or deliver a crafted HTML page to a victim’s browser, implying the attack vector is remote content delivery. Given the seriousness of a sandbox escape and the lack of known public exploits, affected users should prioritize applying the available update as soon as possible.
OpenCVE Enrichment