Impact
A use‑after‑free vulnerability in the Views component of Google Chrome on Windows can lead to heap corruption when a user interacts with a specially crafted HTML page. The flaw is a memory‑management error (CWE‑416) that may allow an attacker to execute arbitrary code on the victim’s machine.
Affected Systems
Google Chrome for Windows versions earlier than 151.0.7922.109 are affected. Users running those builds should update their browser to mitigate the issue.
Risk and Exploitability
The exploit requires a remote attacker to host a malicious web page and convince a user to perform specific UI gestures within Chrome, a scenario that is feasible for phishing or drive‑by websites. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the Chromium security team rates it as High. Given the potential for arbitrary code execution and the realistic attack vector, the risk to affected systems is significant.
OpenCVE Enrichment