Impact
In Chrome versions before 151.0.7922.109, a use‑after‑free flaw in the Views component allows a remote attacker who can coax a user into performing specific UI gestures to trigger heap corruption when loading a crafted HTML page. The flaw is classified as CWE‑416 and carries a Chromium severity rating of High, indicating that the corrupted heap could potentially be leveraged to execute arbitrary code or disrupt the browser process.
Affected Systems
Google Chrome browsers running any revision earlier than 151.0.7922.109 are impacted. No additional vendors or products are listed as affected.
Risk and Exploitability
The vulnerability requires a user to visit a malicious web page and perform certain UI gestures, so it is a user‑interaction‑dependent remote exploitation vector. No EPSS score is available, and the issue is not in the CISA KEV catalog. Because the flaw can corrupt heap objects it may lead to remote code execution if an attacker can craft the appropriate input sequence. Given its high severity and the lack of an availability countermeasure, enterprises should treat it as a high‑risk exploit in the pipeline.
OpenCVE Enrichment