Impact
A use‑after‑free flaw in Google Chrome’s codec implementation allows a remote attacker to read data from process memory via a specially crafted HTML page. This vulnerability (CWE‑416) is a classic memory corruption issue (CWE‑825) that can result in private data leakage without requiring elevated privileges.
Affected Systems
Chrome versions earlier than 149.0.7827.53 on all supported operating systems—Windows, macOS, and Linux—are affected, as the buggy code resides in the core codec library shared across platforms.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1% shows a low likelihood of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker only needs to deliver a malicious HTML page; any Chrome user who opens such a page is potentially vulnerable, and the flaw can lead to memory disclosure without elevated privileges.
OpenCVE Enrichment
Debian DSA