Impact
A use‑after‑free bug in Chrome’s USB handling code on Windows allows a remote attacker to trigger a potential sandbox escape by delivering a specially crafted HTML page. The flaw causes Chrome to access memory that has been freed, undermining the browser’s isolation boundary. The vulnerability is a classic use‑after‑free (CWE-416) and improper resource management (CWE-825).
Affected Systems
The issue affects all Windows users running Google Chrome older than version 149.0.7827.53 on the stable channel. Any installation of the affected version on Windows is potentially exposed.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.6, indicating critical severity. The EPSS score is less than 1%, suggesting a low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. The attack vector is remote, requiring the victim to load a specially crafted HTML page. Based on the description, it is inferred that the page could be delivered via a USB device. Successful exploitation could result in a sandbox escape, allowing the attacker to run code outside Chrome’s sandbox.
OpenCVE Enrichment
Debian DSA