Impact
A use‑after‑free vulnerability (CWE‑416) in the ANGLE graphics layer of Google Chrome on Windows allows a remote attacker to execute arbitrary code within the browser sandbox. The flaw, also related to CWE‑825—improper restriction of operations— is triggered by a specially crafted HTML page that causes a freed GPU resource to be accessed again, giving the attacker code‑execution capabilities with the privileges of the Chrome process.
Affected Systems
Google Chrome installations on Windows that are older than version 149.0.7827.53 are affected. The ANGLE component used by Chrome on Windows is the only location of the bug; other operating systems or non‑Chromium browsers are not impacted.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity. The EPSS score is below 1%, showing a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented wild exploitation to date. The likely attack vector is a remote crafted HTML page served over HTTP or HTTPS; the attacker needs the victim to visit the malicious page to trigger the flaw. Exploitation requires a specific payload, but the high CVSS score alone indicates a realistic risk for users who have not applied the latest patch.
OpenCVE Enrichment
Debian DSA