Impact
A use‑after‑free vulnerability in the Views component of Google Chrome, present in all versions before 149.0.7827.53, permits a remote attacker who has already compromised the renderer process to craft a malicious HTML page that triggers a sandbox escape. The flaw, classified as CWE‑416, can lead to the execution of arbitrary code on the victim’s system, thereby undermining both confidentiality and integrity.
Affected Systems
Google Chrome users running any version older than 149.0.7827.53 on Windows, macOS, or Linux are affected. The vulnerability specifically targets the renderer process of Chrome’s stable channel prior to the noted patch release.
Risk and Exploitability
Chromium rates this issue as high severity. At the time of this assessment the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to already control the renderer process, inferred that this generally involves delivering a specially crafted HTML payload through a compromised site or another exploit. While the attack vector is remote and can be triggered without further user interaction beyond visiting malicious content, the overall risk is considered moderate to high until the affected Chrome versions are updated.
OpenCVE Enrichment