Impact
The vulnerability is a use‑after‑free flaw (CWE‑416) in the ServiceWorker implementation of Google Chrome and involves a memory corruption issue (CWE‑825). An attacker who convinces a user to install a malicious Chrome extension can trigger this flaw, leading to execution of arbitrary code within the Chrome process. The impact is the ability to run code with the privileges of the affected user inside the browser.
Affected Systems
Affected systems are installations of Google Chrome on desktop platforms running any version prior to 149.0.7827.53. This includes all operating systems supported by Chrome; the statement that the flaw applies to all OS is inferred because the CVE description does not restrict to any specific OS.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high severity, and its EPSS score is < 1%, suggesting a very low but non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector involves social engineering, where an attacker persuades a user to install a malicious extension that contains a crafted payload to trigger the use‑after‑free. Once installed, the extension can exploit the flaw to execute code on the user’s machine, leveraging the privilege context of the Chrome process.
OpenCVE Enrichment
Debian DSA