Impact
A use after free vulnerability in the Actor component of Google Chrome exists in versions prior to 149.0.7827.53. An attacker can deliver a specially crafted HTML page that causes the free memory to be accessed, allowing execution of arbitrary code within the sandboxed browser process. This weakness is a classic memory-safety flaw and is classified as CWE‑416. The impact is the execution of code inside a sandbox, which could be leveraged to escape that sandbox or perform malicious actions while the browser controls the user session.
Affected Systems
The flaw affects Google Chrome browsers running any version earlier than 149.0.7827.53. Users on those releases remain exposed until the browser is updated to a fixed build.
Risk and Exploitability
The advisory labels the issue as High severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw is triggered by a crafted HTML page, the likely attack vector is a web‑based exploitation carried out by a remote adversary with access to a web page rendered by Chrome. Exploitation requires a web page that contains the malicious payload and sufficient privileges to load it in the user’s browser. Given the absence of mitigation information, practitioners should assume the risk is significant until the vulnerability is patched.
OpenCVE Enrichment