Impact
The vulnerability is a use‑after‑free flaw in the Skia graphics library used by Google Chrome. An attacker who can compromise a renderer process can use a specially crafted HTML document to execute arbitrary code inside the sandbox. The weakness is identified as CWE‑416.
Affected Systems
Google Chrome versions earlier than 151.0.7922.109 are affected. The flaw applies to all platforms that load compromised renderer processes through normal browsing of malicious content.
Risk and Exploitability
The CVE is rated high severity, with a CVSS score of 7.5, and is not currently listed in the CISA KEV catalog. The EPSS score is not available, so exact exploitation probability is unknown. The exploit requires the attacker to first compromise the renderer process, which is typically achieved with a malicious web page delivered over the network. Once the renderer is subverted, the use‑after‑free can be triggered to execute code within the renderer’s sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA