Impact
This vulnerability is a use‑after‑free flaw in the Viz rendering engine of Google Chrome. When an attacker has already compromised the renderer process, they can exploit the flaw to escape the process sandbox, potentially resulting in remote code execution on the host system.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are vulnerable. The weakness is limited to the renderer component of the browser and does not affect the core browser code directly.
Risk and Exploitability
The flaw is high‑severity (Chromium security severity: High) with a CVSS score of 8.3 and has no publicly documented exploits, but the absence of an EPSS score does not preclude risk. An attacker would need to deliver a crafted HTML page that targets the renderer, implying a remote code‑execution path that requires a prior compromise of the renderer process. The risk is elevated for users running vulnerable Chrome versions on untrusted content, and the vulnerability is not listed in CISA KEV at this time.
OpenCVE Enrichment