Impact
The vulnerability is a use‑after‑free flaw located in Google Chrome's Web Authentication implementation. A crafted HTML page can trigger the defect, which allows a remote attacker to escape the browser sandbox and potentially execute code outside the browser environment. This could compromise confidentiality, integrity, and availability of the affected system, effectively giving the attacker control over the host process.
Affected Systems
Google Chrome browsers running any Chrome version earlier than 151.0.7922.109 on supported platforms are vulnerable. The issue affects all desktop channels (stable, beta, dev) that ship the susceptible Web Authentication code.
Risk and Exploitability
Chromium rates the severity of the issue as high, with a CVSS score of 9.6 and an EPSS score of < 1%. The flaw requires an attacker to supply a malicious HTML document that is processed by the victim's Chrome instance, so it is a remote, user‑supplied code execution scenario. While the EPSS score indicates a low exploitation probability, the high severity and the availability of a patch urge immediate attention. The vulnerability is not listed in CISA KEV as of the latest data.
OpenCVE Enrichment
Debian DLA
Debian DSA