Impact
A use‑after‑free bug in the Blink rendering engine of Google Chrome before version 149.0.7827.53 permits a remote attacker to run code inside the browser’s sandbox by serving a carefully crafted HTML page. This flaw falls under CWE‑416 and CWE‑825 and could compromise the confidentiality, integrity, or availability of a victim’s system if exploited, especially because code can be executed with the privileges granted to the sandboxed renderer.
Affected Systems
Google Chrome users of any platform running a release before 149.0.7827.53 are affected. No additional vendors or product variants are listed in the CNA data.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of 0.0008 (less than 1%) reflects a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is a malicious or compromised web page that is opened or visited by an end‑user, which can trigger the use‑after‑free during the page’s rendering.
OpenCVE Enrichment
Debian DSA