Impact
Use‑after‑free vulnerability in the Views component of Google Chrome on Windows allows an attacker to execute arbitrary code when a victim loads a specially crafted HTML page. The flaw stems from improper memory handling and reference misuse (CWE‑416, CWE‑825), enabling code execution within the browser process and potentially compromising sensitive data or facilitating a deeper system compromise.
Affected Systems
Any Windows installation of Google Chrome with a version earlier than 149.0.7827.53 is vulnerable; macOS, Linux, and newer Chrome releases are not affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. Exploitation requires an attacker to serve a malicious webpage that the user must visit, so success depends on user interaction. The EPSS score is less than 1%, indicating a low probability of active exploitation, and the issue is not listed in the CISA KEV catalog, although the potential for arbitrary code execution within the browser remains significant and warrants prompt remediation.
OpenCVE Enrichment
Debian DSA