Impact
This vulnerability is a use‑after‑free flaw in the font rendering component of Google Chrome on Windows. By loading a specially crafted HTML page, a remote attacker can trigger a memory access after the font object has been freed, allowing execution of arbitrary code inside Chrome’s sandbox. The flaw carries a CVSS score of 8.8, indicating high severity, and the Chromium team classifies it as a medium‑severity security issue. The impact is that an attacker could run code with sandboxed privileges, potentially elevating privileges or exfiltrating data if further vulnerabilities are leveraged.
Affected Systems
The flaw affects Google Chrome running on Windows systems with versions earlier than 155.0.8059.39. Only desktop builds of the stable channel are impacted according to the release notes. The vulnerability is specific to the font rendering engine in those Chrome releases.
Risk and Exploitability
The CVSS score of 8.8 places this bug in the high‑risk range, and the lack of an EPSS score means its current exploitation probability is uncertain. The flaw is listed as not being part of the CISA KEV catalog. Attackers could exploit the vulnerability by serving a malicious web page to a victim who has Chrome installed and is willing to view it, thereby triggering the use‑after‑free during font processing. Given that the flaw requires crafted page delivery and that normal browser updates will fix it, the risk is mitigated by applying the patch promptly.
OpenCVE Enrichment