Impact
Google Chrome contains a use‑after‑free flaw in the Glic component that allows an attacker to craft an HTML page which triggers the vulnerability. Exploitation results in arbitrary code execution inside the browser sandbox. The weakness is identified as CWE‑416 and is rated as high severity by Chromium security.
Affected Systems
The vulnerability affects Google Chrome versions earlier than 149.0.7827.53 on all supported platforms. Users running these versions are at risk until they upgrade to the patched release.
Risk and Exploitability
The attack vector is remote via a manipulated HTML page served over the network. Exploitation is confined to the browser sandbox, enabling arbitrary code execution inside that sandbox. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, but the high CVSS‑based severity indicates that a coordinated exploit is plausible.
OpenCVE Enrichment