Impact
The vulnerability is a use‑after‑free flaw in the ANGLE component used by Google Chrome; a malicious web page can trigger heap corruption that may lead to arbitrary code execution or a denial‑of‑service within the browser process, and it is identified as CWE‑416.
Affected Systems
Google Chrome versions earlier than 144.0.7559.59 are affected on macOS, Windows, and Linux platforms where ANGLE is used, regardless of operating system.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is high severity, yet the EPSS score is below 1 % and it is not present in the CISA KEV catalog, indicating a currently low exploitation probability. The remote attack vector relies on a crafted HTML page, which could be delivered via phishing or compromised sites, and successful exploitation would bypass sandboxing and allow arbitrary code execution, raising the risk for active users until the browser is updated.
OpenCVE Enrichment
Debian DSA