Impact
A heap buffer overflow in the Base component of Google Chrome up to version 151.0.7922.109 allows an attacker who convinces a user to install a malicious extension to corrupt the heap. The detected weaknesses are a classic heap buffer overflow (CWE-122) and an out-of-bounds write (CWE-787). If successfully exploited, this could lead to arbitrary code execution or a denial-of-service condition in the compromised browser process.
Affected Systems
Google Chrome browsers on desktop platforms that have not yet been updated to version 151.0.7922.109. The vulnerability applies to the base component included in the stable channel builds delivered through Chrome updates.
Risk and Exploitability
The vulnerability carries a high severity rating in Chromium’s internal security score. The EPSS score indicates a very low exploitation probability of less than 1%, yet the attack vector is client-side and relies on users installing a malicious extension, a low-barrier scenario for social engineering. The knowledge that exploitable heap corruption can be triggered via extension code makes this a significant risk, though it remains absent from CISA’s KEV catalog. The weaknesses stem from a classic heap buffer overflow (CWE-122) and an out-of-bounds write (CWE-787). Google has released a patch in Chrome version 151.0.7922.109, so the flaw is remediated for users who apply the update.
OpenCVE Enrichment
Debian DLA
Debian DSA