Impact
The vulnerability is a use‑after‑free error in the Chromoting component of Google Chrome on Windows (CWE‑416). When Chrome processes specially crafted network traffic, the flaw can be triggered, allowing an attacker to execute arbitrary code with the privileges of the browser process. Chromium has rated the problem as High severity.
Affected Systems
Google Chrome on Windows versions older than 149.0.7827.53 are affected; no other vendors or products are mentioned in the data.
Risk and Exploitability
Because the flaw can be triggered by remote network traffic, an attacker can exploit it from outside the victim’s machine, turning it into a remote code execution vector. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high severity rating and lack of a mitigated supersession mean that unpatched systems remain at risk. The official Chrome stable channel update includes a patch for the issue, so installing the update is the definitive countermeasure.
OpenCVE Enrichment