Impact
A use‑after‑free flaw was identified in the Password Manager component of Google Chrome prior to version 149.0.7827.53. The vulnerability allows a remote attacker to trigger arbitrary code execution inside the browser’s sandbox when a specially crafted HTML page is loaded. The weakness is a classic use‑after‑free scenario (CWE‑416). The impact is that malicious code can run with the privileges granted to the sandboxed process. The flaw is rated Medium by Chromium security severity but remains a significant threat due to its high CVSS score.
Affected Systems
Google Chrome users running any stable channel build older than 149.0.7827.53 are affected. The flaw is tied specifically to the Password Manager component and only impacts installations that have this component enabled in the affected Chrome version range.
Risk and Exploitability
The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits. The CVSS score is 8.8, indicating high severity. The likely attack vector is a remote attacker delivering a malicious HTML page that a user opens or visits, which then triggers the use‑after‑free in the sandboxed Password Manager code.
OpenCVE Enrichment
Debian DSA