Impact
A heap buffer overflow in the Base component of Google Chrome up to version 151.0.7922.109 allows an attacker who convinces a user to install a malicious extension to corrupt the heap. The detected weakness is a classic heap overflow (CWE-122). If successfully exploited, this could lead to arbitrary code execution or a denial‑of‑service condition in the compromised browser process.
Affected Systems
Google Chrome browsers on desktop platforms that have not yet been updated to version 151.0.7922.109. The vulnerability applies to the base component included in the stable channel builds delivered through Chrome updates.
Risk and Exploitability
The vulnerability carries a high severity rating in Chromium’s internal security score. Although an EPSS score is not available, the attack vector is clearly client‑side and relies on users installing a malicious extension, which is a low‑barrier scenario for social engineering. The knowledge that exploitable heap corruption can be triggered via extension code makes this a significant risk, though it is not listed in CISA’s KEV catalog. Vendors have not yet released a patch; therefore, the flaw remains available to potential attackers.
OpenCVE Enrichment