Impact
A use‑after‑free bug in the graphics subsystem of Google Chrome on Linux allows a remote attacker to corrupt the heap by loading a specially crafted HTML page. The resulting heap corruption could lead to arbitrary code execution or other disruptive behavior. The weakness is classified as CWE‑416, indicating a use after free condition that can be exploited by an attacker controlling input to the browser. The vulnerability is listed by Chromium as Critical.
Affected Systems
Google Chrome on Linux prior to version 149.0.7827.53 is affected. The issue exists in all Linux builds of Chrome’s stable channel that ship with that or earlier renderer, and it is not present once the browser is updated to 149.0.7827.53 or later.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity. No EPSS score is available, and the vulnerability is not in CISA’s KEV catalog, so public exploitation may be uncertain, but the potential impact remains significant. A likely attack vector is a malicious web page or an untrusted local file that the victim opens in Chrome, leading to remote code execution when the use‑after‑free condition is triggered.
OpenCVE Enrichment