Impact
A use‑after‑free flaw in the ANGLE graphics layer of Google Chrome versions prior to 149.0.7827.53 can be exploited by a remote attacker who has already compromised the renderer process to escape the sandbox and obtain higher privilege. The weakness is a classic CWE‑416 condition and a related CWE‑825 memory management flaw, and has been rated Medium severity by the Chromium security team.
Affected Systems
Chromium‑based browsers running Google Chrome, with affected releases being any version before Chrome 149.0.7827.53. Based on the description, the vulnerability likely applies to desktop environments. The security patch was rolled out in the 149.0.7827.53 update released by the stable channel.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating no current evidence of widespread exploitation. The CVSS score of 9.6 highlights a high severity level for this flaw. The attack path requires the attacker to first compromise the renderer process. Based on the description, it is inferred that the probability of successful exploitation is moderate. Once the renderer is compromised, the sandbox escape can lead to full system control on the affected device.
OpenCVE Enrichment
Debian DSA