Impact
Use‑after‑free vulnerability in the Views component of Google Chrome on Windows allows an attacker to execute arbitrary code when a victim loads a specially crafted HTML page. The flaw stems from improper memory handling and reference misuse (CWE‑416), enabling code execution the browser process and potentially compromising sensitive data or facilitating a deeper system compromise.
Affected Systems
Any Windows installation of Google Chrome with a version earlier than 149.0.7827.53 is vulnerable; this inference comes from the description stating "prior to 149.0.7827.53". macOS, Linux, and newer Chrome releases are not affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. Exploitation requires an attacker to serve a malicious webpage that the user must visit, so success depends on user interaction. EPSS information is not available and the issue is not listed in the CISA KEV catalog, limiting evidence of active exploitation, but the potential for arbitrary code execution within the browser remains significant, warranting prompt remediation.
OpenCVE Enrichment