Impact
A use‑after‑free vulnerability was discovered in the Aura graphics subsystem of Google Chrome on Linux. The flaw can be triggered by a crafted HTML page, allowing a remote attacker to potentially escape the browser sandbox and execute code with the same privileges as the browsing user. The weakness is categorized as CWE‑416 and CWE‑825, indicating misuse of freed memory and unsafe memory management that can lead to arbitrary code execution.
Affected Systems
All installations of Google Chrome running versions prior to 151.0.7922.109 on Linux are affected. The vulnerability was identified in the Aura subsystem, which is used by all modern Chrome builds on this platform.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity and could lead to full system compromise if exploited. The EPSS score of < 1% indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Attackers would need to host or deliver a crafted HTML page to a victim’s browser, implying the attack vector is remote content delivery. Given the seriousness of a sandbox escape and the lack of known public exploits, affected users should prioritize applying the available update as soon as possible.
OpenCVE Enrichment
Debian DLA
Debian DSA