Impact
A use after free vulnerability in the Actor component of Google Chrome exists in versions prior to 149.0.7827.53. An attacker can deliver a specially crafted HTML page that causes the free memory to be accessed, allowing execution of arbitrary code within the sandboxed browser process. This weakness is a classic memory-safety flaw and is classified as CWE‑416 and CWE‑825. The impact is the execution of code inside a sandbox, which could be leveraged to escape that sandbox or perform malicious actions while the browser controls the user session.
Affected Systems
The flaw affects Google Chrome browsers running any version earlier than 149.0.7827.53. Users on those releases remain exposed until the browser is updated to a fixed build.
Risk and Exploitability
The advisory labels the issue as High severity. The EPSS score indicates a very low exploitation probability (<1%), and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw is triggered by a crafted HTML page, the likely attack vector is a web‑based exploitation carried out by a remote adversary with access to a web page rendered by Chrome. Exploitation requires a web page that contains the malicious payload and sufficient privileges to load it in the user’s browser. Given the vulnerability’s high CVSS score, practitioners should consider the risk significant until the vulnerability is patched.
OpenCVE Enrichment
Debian DSA