Impact
A use‑after‑free flaw in the Ozone rendering backend of Google Chrome prior to version 149.0.7827.53 allows a remote attacker to execute arbitrary code by presenting a crafted HTML page. The vulnerability is identified as CWE‑416 (Use After Free) and is assigned a CVSS score of 8.8, indicating high severity. Chromium identifies the issue as critical, implying that exploitation could compromise the user’s system.
Affected Systems
Google Chrome browsers running a version earlier than 149.0.7827.53 are susceptible. This includes all stable channel releases on desktop platforms until that point in the 149.x series.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The CVE does not provide specific details regarding the existence of public exploits or authentication requirements; analysis of risk should therefore consider the high severity rating and the potential for remote code execution via a crafted HTML page.
OpenCVE Enrichment