Impact
The vulnerability is a use‑after‑free flaw in the Extensions component of Google Chrome prior to version 151.0.7922.137. An attacker who convinces a user to install a malicious extension can trigger the flaw and execute arbitrary code within the browser sandbox, leveraging the CWE‑416 weakness. This allows compromise of confidentiality, integrity, or availability if the sandbox is bypassed or the extension accesses privileged APIs.
Affected Systems
The affected product is the Google Chrome desktop browser on Windows, macOS and Linux. Every installation running a version earlier than 151.0.7922.137 is vulnerable; the fix is delivered through Chrome’s regular update channel.
Risk and Exploitability
The CVSS score is 7.5 and the EPSS score is less than 1%, indicating a low exploitation probability at present, and the issue is not listed in the CISA KEV catalogue. The attack typically involves social engineering to persuade the user to install a malicious extension via phishing or deceptive web content. Once installed, the use‑after‑free can be triggered to run arbitrary code within the browser sandbox, potentially leading to privilege escalation if the sandbox is compromised.
OpenCVE Enrichment
Debian DLA
Debian DSA