Impact
The vulnerability is a use‑after‑free flaw in the V8 JavaScript engine of Google Chrome. A crafted HTML page can trigger the flaw, allowing a remote attacker to execute arbitrary code inside the browser sandbox. The exploit could lead to system compromise if the sandbox is bypassed, and the problem carries a CVSS score of 8.8, signifying high severity.
Affected Systems
Google Chrome versions prior to 151.0.7922.137 are affected. Systems running the browser on any platform, including Windows, macOS, Linux, and mobile, are at risk when they expose the vulnerable engine to untrusted web content.
Risk and Exploitability
The EPSS score of less than 1 % suggests a low probability of widespread exploitation at the present time, and the vulnerability is not listed in CISA’s KEV catalog. However, given the high CVSS score and the fact that the attack requires a crafted HTML page, which can be delivered over the Internet or through phishing, the risk to exposed systems remains significant. The attacker must have the ability to influence the victim’s browser, making a direct web‑content attack the most likely vector.
OpenCVE Enrichment
Debian DLA
Debian DSA