Impact
A use‑after‑free bug in the DOM handling code path of Google Chrome allows a remote attacker who can serve a crafted HTML page to execute arbitrary code inside the browser’s sandbox. The vulnerability is a classic use‑after‑free flaw (CWE‑416) and involves improper use of uninitialized memory (CWE‑825), providing a memory corruption that can be triggered without user interaction beyond loading the malicious page. When exploited, the attacker gains code execution within the confined sandbox, enabling further attacks such as credential theft or lateral movement if the sandbox is circumvented.
Affected Systems
Google Chrome versions prior to 151.0.7922.173 are affected. The issue appears on the stable channel, and the advisory indicates that the security update was released for this release line.
Risk and Exploitability
The vulnerability is characterized as high severity by Chromium, with a CVSS score of 8.8, and an EPSS score of < 1%. It is not listed in the CISA KEV catalog. The likely attack vector is a crafted HTML page delivered over the network; an attacker would need to entice a user to load the page or deliver it via an infected site. Because the exploitation is confined to the sandbox, the damage is mitigated compared to full system compromise but still poses a significant risk to user data and application integrity.
OpenCVE Enrichment
Debian DLA
Debian DSA