Impact
A use‑after‑free bug in the ANGLE graphics library of Google Chrome for Windows permits a remote attacker to trigger arbitrary code execution within the Chrome sandbox through a maliciously crafted HTML page. The flaw violates protecting memory after it has been freed and is classified as CWE‑416. If exploited, the attacker could gain the same privileges as the process, potentially allowing full system compromise from web content.
Affected Systems
Affected are users running Google Chrome on Windows with versions preceding 149.0.7827.53. The 149.0.7827.53 release and later provide the necessary patch to eliminate the free‑use vector.
Risk and Exploitability
The vulnerability carries a high severity rating from Chromium; the CVSS score of 8.8 indicates high risk. Although no EPSS score is currently available, its exploitation requires only a crafted web page which could be served via any HTTP or HTTPS site. The lack of a CISA KEV listing does not reduce the risk of immediate exposure. Attackers can exploit the flaw remotely by enticing users to open malicious URLs, after which the sandbox escape grants elevated privileges.
OpenCVE Enrichment