Impact
The vulnerability is a use‑after‑free in the Chromoting component of Google Chrome before version 149.0.7827.53. It allows a malicious remote actor to send crafted network traffic that can cause the browser to execute code with the privileges of the user, leading to full system compromise—data theft, manipulation, and lateral movement. The flaw maps to CWE‑416.
Affected Systems
Google Chrome on Windows, macOS, and Linux desktop versions prior to 149.0.7827.53 are affected. Any installation of Chrome built on the stable channel before that release is vulnerable.
Risk and Exploitability
No EPSS data is available, and the issue is not listed in the CISA KEV catalog. The Chromoting use‑after‑free is triggered by remote network traffic and can lead to arbitrary code execution upon reception of malicious data. Even though Chromium rates the severity as medium internally, the potential impact and the exploit path imply a high risk if an attacker can force the victim to process malicious traffic.
OpenCVE Enrichment