Impact
Use after free in the Compositing component of Google Chrome version 149.0.7827.53 and earlier allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This flaw is a classic use‑after‑free vulnerability (CWE‑416). The attacker could run malicious code under the browser’s sandbox privileges, potentially compromising the user’s machine if sandbox escape is achieved.
Affected Systems
Google Chrome browsers running any version earlier than 149.0.7827.53 are affected. This includes all standard Chrome stable releases for desktop operating systems.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation detected yet. The likely attack vector is a remote web page that loads crafted content presented to the user. Successful exploitation would allow code execution within the browser sandbox and possibly lead to privilege escalation if the sandbox is bypassed.
OpenCVE Enrichment