Impact
The vulnerability is a use‑after‑free bug in the Chromoting component of Google Chrome versions earlier than 151.0.7922.173. It allows a remote attacker to send specially crafted network traffic that frees a memory object and then re‑uses its pointer to execute code outside the browser sandbox. The flaw is classified as CWE‑416 and can give attackers full control over the user’s system, compromising confidentiality, integrity and availability.
Affected Systems
The flaw affects desktop editions of Google Chrome running Windows, macOS or Linux where the Chromoting feature (remote desktop/remote assistance) is enabled. All Chrome versions released before 151.0.7922.173 are vulnerable; the patched release begins with 151.0.7922.173.
Risk and Exploitability
The bug has a CVSS score of 8.8, indicating a critical severity. The EPSS score is < 1% and the vulnerability is not listed in CISA's KEV catalog, but the fact that it can be exploited through network traffic makes it high risk. Attackers could hijack the browser process, escape the sandbox, and run arbitrary code on the victim’s machine.
OpenCVE Enrichment
Debian DLA
Debian DSA