Impact
A use‑after‑free vulnerability exists in Google Chrome’s FileSystem API in versions prior to 149.0.7827.53. The flaw allows a remote attacker to exploit a crafted HTML page loaded into Chrome, potentially escaping the sandbox that normally isolates web content. This sandbox escape can enable the attacker to execute arbitrary code with the privileges of the user’s Chrome process. The weakness is classified as CWE‑416 and CWE‑825.
Affected Systems
All installations of Google Chrome running a version older than 149.0.7827.53 on any supported operating system are susceptible, regardless of user‑account privileges.
Risk and Exploitability
The CVSS score of 9.6 indicates high severity, and the EPSS score is less than 1%, suggesting a very low probability of exploitation at the current moment. The vulnerability is not listed in CISA’s KEV catalog, but the high severity rating indicates that once exploit code is available attackers have a strong incentive to target this flaw. The likely attack vector is a remote attacker delivering a malicious HTML page; no additional configuration or privileged access is required beyond normal browsing activity.
OpenCVE Enrichment
Debian DSA