Impact
An object lifecycle flaw in Chrome's Dawn rendering engine can let a remote attacker supply specially crafted HTML to escape the content sandbox, potentially allowing code execution with higher privileges inside the browser. The vulnerability is a use‑after‑free or related condition, aligning with CWE‑416, and could compromise confidentiality, integrity, or availability if leveraged.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected. The flaw resides in the Dawn component of the Chrome rendering engine, impacting all platforms that use it and placing any user browsing the Web with an unpatched version at risk.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, while the CVSS score of 9.6 reflects a high severity and high impact should the flaw be exploited. The vulnerability is not listed in the CISA KEV catalog. The Chromium severity is Medium, indicating significant risk from a potential sandbox escape if an attacker delivers malicious content. Public evidence of exploitation is lacking, but the absence of a known exploit does not diminish the risk. Attackers would need to craft malicious HTML that triggers the lifetime bug, typically delivered via a compromised or malicious site.
OpenCVE Enrichment
Debian DSA