Impact
A use‑after‑free flaw in the WebXR implementation of Google Chrome allows a remote attacker to execute arbitrary code within the browser sandbox by loading a specially crafted HTML page.
Affected Systems
The vulnerability affects all Chrome releases before version 149.0.7827.53, including older 148.x builds and any 149.x build that has not yet applied the patch. Any system running these versions is potentially susceptible.
Risk and Exploitability
The flaw is rated high severity by Chromium and is exploitable via a normal web page served to a user, enabling an attacker to run code at the sandbox level. The CVE is not listed in CISA’s KEV catalog, but the high severity and direct execution vector underscore a significant risk.
OpenCVE Enrichment