Impact
A use‑after‑free flaw in the PDF rendering engine of Google Chrome allows a remote attacker to execute arbitrary code inside the sandbox through a crafted HTML page. The vulnerability can lead to complete compromise of the affected browser instance. It is classified as a high‑severity flaw (CWE-416).
Affected Systems
Google Chrome versions prior to 155.0.8059.39 are affected. The flaw exists in the PDF handling subsystem, and any user who opens a maliciously crafted HTML page that references a PDF can be targeted.
Risk and Exploitability
The standard CVSS score of 8.8 indicates a high severity, and the vulnerability is not currently listed in the CISA KEV catalog. The EPSS score is unavailable, but the nature of the flaw suggests that exploitation requires an attacker-controlled web page to be accessed by a user. Because the attack leverages the browser’s PDF renderer, it is limited to users who load the malicious page, yet the impact remains significant if exploited.
OpenCVE Enrichment