Impact
This vulnerability is a use‑after‑free flaw in the Updater module of Google Chrome on Windows. It allows a local attacker to place a malicious file that is then executed with elevated privileges, giving the attacker OS‑level access. The flaw results from a corrupted reference that is freed but subsequently used, enabling privileged execution.
Affected Systems
Google Chrome browsers running on Windows that are earlier than version 149.0.7827.53 are affected. The issue resides in the updater component executed during installation and update procedures.
Risk and Exploitability
The CVSS score assigned to this flaw is 7.3, indicating a high severity. The EPSS score is reported as < 1%, implying a very low probability of exploitation in the wild. The vulnerability requires local access; an attacker must be present on the target machine or have logged‑in credentials to place the malicious file. The flaw is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
Debian DSA