Impact
Use after free in the Compositing component of Google Chrome version 149.0.7827.53 and earlier allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This flaw is a classic use‑after‑free vulnerability (CWE‑416) and also involves missing access control (CWE‑825). The attacker could run malicious code under the browser’s sandbox privileges, potentially compromising the user’s machine if sandbox escape is achieved.
Affected Systems
Google Chrome browsers running any version earlier than 149.0.7827.53 are affected. This includes all standard Chrome stable releases for desktop operating systems on Windows, macOS, and Linux.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet. The likely attack vector is a remote web page that loads crafted content presented to the user. Successful exploitation would allow code execution within the browser sandbox and possibly lead to privilege escalation if the sandbox is bypassed.
OpenCVE Enrichment
Debian DSA