Impact
The vulnerability is a use‑after‑free in the FullScreen handling code of Google Chrome on Windows, affecting all builds prior to 149.0.7827.53. An attacker who has already compromised the renderer process can trigger the flaw with a crafted HTML page, potentially escaping the process sandbox and executing code with the renderer’s privileges. The weakness is identified as CWE‑416, a classic use‑after‑free memory error.
Affected Systems
Google Chrome for Windows users running any channel (stable, beta, dev) with a version earlier than 149.0.7827.53 are impacted. The issue applies to desktop installations where the renderer process is accessible, regardless of user privileges or sandbox configuration.
Risk and Exploitability
The flaw is rated high severity; the CVSS score is 8.3. The EPSS metric is unavailable and the vulnerability is not listed in CISA’s KEV catalog, indicating no widely known exploitation yet. The attack vector is inferred to be a remote crafted HTML page that an attacker can serve, combined with a prior compromise of the renderer process. If both conditions are satisfied, the exploit could lead to sandbox escape and arbitrary code execution on the host. Although exploitation evidence is limited, the potential impact is significant, warranting immediate attention.
OpenCVE Enrichment