Impact
A use‑after‑free vulnerability exists in the Views component of Google Chrome in versions older than 151.0.7922.109. The flaw, classified as CWE‑416 and CWE‑825, permits a remote attacker who has already compromised the renderer process to craft a malicious HTML document that, when rendered, can access freed memory. This may allow the attacker to escape the browser sandbox and gain higher privileges within the browsing context.
Affected Systems
Google Chrome users on any operating system running a build prior to version 151.0.7922.109 are affected. The issue applies to all installations of those older releases until the fix is applied.
Risk and Exploitability
The EPSS score is < 1%, indicating a low but non‑zero probability of exploitation. The CVSS score is 8.3. Chromium labels the flaw as Critical, and it is not listed in CISA’s KEV catalog. Exploitation requires an attacker to first gain control of a renderer process; subsequently, loading a specially crafted HTML page can trigger the use‑after‑free and potentially break out of the sandbox. No additional user interaction beyond opening the malicious page is mentioned in the description.
OpenCVE Enrichment
Debian DLA
Debian DSA