Impact
The vulnerability is a use‑after‑free in the Chromoting component of Google Chrome before version 149.0.7827.53. It allows a malicious remote actor to send crafted network traffic that can cause the browser to execute code with the privileges of the user, leading to full system compromise—data theft, manipulation, and lateral movement. The flaw maps to CWE‑416 and CWE‑825.
Affected Systems
Google Chrome on Windows, macOS, and Linux desktop versions prior to 149.0.7827.53 are affected. Any installation of Chrome built on the stable channel before that release is vulnerable.
Risk and Exploitability
The use‑after‑free flaw in Chrome's Chromoting component can be triggered by malicious network traffic, allowing a remote attacker to craft packets that cause the browser to execute code with the user's privileges. With a CVSS score of 8.8, the exploit would grant full system compromise. The EPSS score of <1% indicates a low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential impact remains high, particularly in environments where Chrome is heavily used.
OpenCVE Enrichment
Debian DSA