Impact
A use-after-free flaw exists in the Autofill subsystem of Google Chrome versions before 149.0.7827.53. If an attacker has already compromised the renderer process, they can craft a malicious HTML page that triggers this flaw, potentially enabling a sandbox escape. The vulnerability is a classic use-after-free condition (CWE‑416) and can lead to the execution of arbitrary code beyond the renderer sandbox, affecting confidentiality and integrity of the system.
Affected Systems
The affected vendor/product is Google Chrome. All installations running Chrome versions older than 149.0.7827.53 on any supported desktop platform are vulnerable. No specific patch version is provided in the CNA data, but the advisory references a release that includes the fix.
Risk and Exploitability
The EPSS score is not available, so current exploitation probability is unknown, and the issue is not listed in the CISA KEV catalog. The advisory labels the severity as medium. The attack requires the attacker to gain control of the renderer process first; once that is achieved, the crafted page can exploit the use-after-free to escape the sandbox. Given that the vulnerability relies on prior compromise of a renderer, it is less likely to be widely exploitable in the wild.
OpenCVE Enrichment