Impact
A use‑after‑free flaw in the ANGLE graphics engine of Google Chrome on Windows allows an attacker to execute arbitrary code inside Chrome’s sandbox through a specially crafted HTML page. The vulnerability permits the browser to free a memory object prematurely, enabling malicious code to run once the crafted content is loaded.
Affected Systems
Google Chrome users on Windows running a version earlier than 149.0.7827.53 are vulnerable, as the ANGLE implementation bundled with that release does not contain the fix.
Risk and Exploitability
The CVE has a CVSS score of 8.8 and an EPSS score of less than 1 %. It is not listed in the CISA KEV catalog. The attack requires an externally supplied HTML page that the victim must load; this is inferred from the description, which indicates exploitation via a crafted web page. The impact is confined to sandboxed execution, but the attacker can still perform malicious actions within that privilege level, making the risk significant for impacted users.
OpenCVE Enrichment
Debian DSA