Impact
The flaw is a use‑after‑free bug in the V8 JavaScript engine in Google Chrome versions prior to 149.0.7827.53. When a malicious Chrome Extension is installed, the engine can free memory and later access it again, allowing the attacker to run arbitrary code inside the sandboxed environment. The vulnerability is classified as CWE‑416 and CWE‑825 and carries a medium severity rating from Chromium security.
Affected Systems
Google Chrome on desktop platforms, specifically all stable channel releases before 149.0.7827.53. Users with earlier builds are affected; updated releases have the fix in place.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity and suggests that exploitation could lead to significant impact if achieved. The risk is high because exploitation requires the user to install a malicious extension, typically involving social engineering or a compromised extension source. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, meaning no known widespread exploitation. However, because the attack vector depends on user behavior, the threat remains significant for environments that allow unrestricted extension installation.
OpenCVE Enrichment
Debian DSA