Impact
This vulnerability is a use‑after‑free flaw in the Blink rendering engine of Google Chrome that allows an attacker to execute arbitrary code inside the browser sandbox. The flaw can be triggered by a maliciously crafted HTML page that the user opens, resulting in the attacker gaining code execution privileges within the sandboxed environment. The weakness is identified as CWE‑416 and CWE‑825 and is categorized with a high severity level. The affected code path involves improper memory deallocation where freed memory can still be referenced, enabling the execution of arbitrary code once the attacker’s crafted page is processed by Blink.
Affected Systems
Google Chrome versions prior to 151.0.7922.137 are affected. Users running those versions are vulnerable to exploitation through malformed HTML content.
Risk and Exploitability
The CVSS score of 8.8 indicates a High severity impact, while the EPSS score of less than 1% suggests that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. A remote attacker could exploit the flaw by delivering a malicious web page via a compromised website to a user who has the vulnerable browser installed. If successful, code would execute inside the browser sandbox, potentially leading to privilege escalation within the sandbox environment. The official advisory indicates that the issue has been fixed in Chrome 151.0.7922.137, and no workarounds have been released.
OpenCVE Enrichment
Debian DLA
Debian DSA