Impact
A use‑after‑free vulnerability in the Views component of Google Chrome on Windows can lead to heap corruption when a user interacts with a specially crafted HTML page. The flaw is a memory‑management error (CWE‑416) that may allow an attacker to execute arbitrary code on the victim’s machine. This issue also involves an improperly handled resource cleanup (CWE‑825).
Affected Systems
Google Chrome for Windows versions earlier than 151.0.7922.109 are affected. Users running those builds should update their browser to mitigate the issue.
Risk and Exploitability
The exploit requires a remote attacker to host a malicious web page and convince a user to perform specific UI gestures within Chrome, a scenario that is feasible for phishing or drive‑by websites. The EPSS score is < 1% and the CVSS score is 7.5, classifying the vulnerability as high severity; it is not listed in the CISA KEV catalog, but the Chromium security team rates it as High. Given the potential for arbitrary code execution and the realistic attack vector, the risk to affected systems remains significant.
OpenCVE Enrichment
Debian DLA
Debian DSA