Impact
In Chrome versions before 151.0.7922.109, a use‑after‑free flaw in the Views component allows a remote attacker who can coax a user into performing specific UI gestures to trigger heap corruption when loading a crafted HTML page. The flaw is classified as CWE-416 and CWE-787 and carries a Chromium severity rating of High. Based on the description, it is inferred that the corrupted heap could potentially allow arbitrary code execution or disrupt the browser process, but the CVE does not explicitly confirm such exploitation.
Affected Systems
Google Chrome browsers running any revision earlier than 151.0.7922.109 are impacted. No additional vendors or products are listed as affected.
Risk and Exploitability
The vulnerability requires a user to visit a malicious web page and perform certain UI gestures, so it is a user‑interaction‑dependent remote exploitation vector. The EPSS score is less than 1%, and the issue is not in the CISA KEV catalog. It carries a CVSS score of 7.5, reflecting its high severity. Based on the CVE description, it is inferred that the heap corruption could potentially enable code execution if an attacker crafts an appropriate input sequence, but this is not explicitly confirmed. Enterprises should treat it as a high‑risk exploit in the pipeline.
OpenCVE Enrichment
Debian DLA
Debian DSA