Impact
The vulnerability is a use-after-free bug in the Chrome Base component on Linux prior to version 149.0.7827.53. If an attacker has already compromised the renderer process, the flaw allows reading arbitrary memory in that process, which may contain sensitive information. The weakness is cataloged as CWE-416 and CWE-825, indicating memory corruption vulnerabilities.
Affected Systems
Google Chrome running on Linux environments, any version earlier than 149.0.7827.53, is affected. No other vendors or operating systems are listed as impacted.
Risk and Exploitability
The flaw requires an existing compromise of the renderer process, meaning the attacker must first reach the browser environment. The EPSS score is less than 1%, indicating a very low exploitation likelihood, while the CVSS score of 8.8 classifies the vulnerability as high severity. The issue is not listed in the CISA KEV catalog. Consequently, the risk of confidential data exposure remains significant, justifying prompt remediation.
OpenCVE Enrichment
Debian DSA