Impact
A use‑after‑free flaw exists in the Autofill subsystem of Google Chrome versions before 149.0.7827.53. If an attacker has already compromised the renderer process, they can craft a malicious HTML page that triggers this flaw, potentially enabling a sandbox escape. The vulnerability is a classic use‑after‑free condition (CWE‑416) and can lead to the execution of arbitrary code beyond the renderer sandbox, affecting confidentiality and integrity of the system.
Affected Systems
The affected vendor/product is Google Chrome. All installations running Chrome versions older than 149.0.7827.53 on any supported desktop platform are vulnerable. No specific patch version is provided in the CNA data, but the advisory references a release that includes the fix.
Risk and Exploitability
The CVSS score is 8.3, indicating a high severity. The EPSS score is < 1%, indicating a very low exploitation probability. This vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker to gain control of the renderer process first; once that is achieved, the crafted page can exploit the use‑after‑free to escape the sandbox. Given that the vulnerability relies on prior compromise of a renderer, it is less likely to be widely exploitable in the wild.
OpenCVE Enrichment
Debian DSA