Impact
A use‑after‑free flaw exists in the PDF rendering component of Google Chrome. When a malicious PDF file is processed, an attacker can run arbitrary code inside the browser’s sandbox. The vulnerability is classified as high severity and allows powerful post‑exploitation actions with the same privileges the browser process possesses.
Affected Systems
The flaw affects Google Chrome prior to version 155.0.8059.39. Users running any older Chrome release are susceptible until they upgrade to a patched build.
Risk and Exploitability
The attack vector is remote; a crafted PDF file delivered to a victim’s machine can trigger the flaw. Although the exploitation is confined to the sandbox, it still grants the attacker execution capabilities that can be leveraged to compromise the host. The CVSS score is 8.8, indicating high severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the high severity rating underscores the potential for serious security incidents.
OpenCVE Enrichment