Impact
A use‑after‑free flaw in the WebXR implementation of Google Chrome, which also involves a buffer overread (CWE‑825), allows a remote attacker to execute arbitrary code within the browser sandbox by loading a specially crafted HTML page.
Affected Systems
The vulnerability affects all Chrome releases before version 149.0.7827.53, including older 148.x builds and any 149.x build that has not yet applied the patch. Any system running these versions is potentially susceptible.
Risk and Exploitability
The flaw is rated high severity by Chromium and is exploitable via a normal web page served to a user, enabling an attacker to run code at the sandbox level. The EPSS score is < 1%, indicating a very low exploitation probability, but the high severity and direct execution vector still represent a significant risk. The CVE is not listed in CISA’s KEV catalog. This issue maps to a use‑after‑free (CWE‑416) and a buffer overread (CWE‑825).
OpenCVE Enrichment
Debian DSA