Impact
This vulnerability is a use‑after‑free flaw in the Viz rendering engine of Google Chrome. When an attacker has already compromised the renderer process, they can exploit the flaw to escape the process sandbox, potentially resulting in remote code execution on the host system.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are vulnerable. The weakness is limited to the renderer component of the browser and does not affect the core browser code directly.
Risk and Exploitability
The flaw has a CVSS score of 8.3, indicating high severity. The EPSS score is <1%, reflecting a very low probability that this vulnerability will be exploited in the wild. Nevertheless, an attacker who has already compromised the renderer process could exploit the use‑after‑free in Viz by delivering a crafted HTML page, potentially enabling a sandbox escape. The risk remains significant for users of vulnerable Chrome versions who view untrusted content, but the low EPSS suggests that exploitation is not widespread. The vulnerability is not included in CISA KEV.
OpenCVE Enrichment
Debian DSA