Impact
Use‑after‑free in the HTML rendering engine of Google Chrome before version 151.0.7922.137 enables a remote attacker to execute arbitrary code inside the browser’s sandbox. The flaw, classified as CWE‑416, involves an object being freed while still in use, allowing the attacker to overwrite memory and compromise the integrity of the process, potentially leaking data.
Affected Systems
Only Google Chrome browsers running a version older than 151.0.7922.137 are vulnerable. The vulnerability was fixed in the Chrome 151.0.7922.137 release; all users of older builds on any operating system should upgrade to that version or later.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered High. However, the EPSS score of less than 1% indicates that exploitation attempts are currently rare and the risk of a successful exploit is low. The flaw is not listed in the CISA KEV catalogue. Attackers would likely need to trick a victim into opening a malicious HTML page delivered over the web or via email; the exploit requires no additional privileges and is therefore relatively straightforward when the attack vector is accessible.
OpenCVE Enrichment
Debian DLA
Debian DSA