Impact
This vulnerability is a use‑after‑free flaw located in the Chromoting component of Google Chrome on Linux. By delivering specially crafted network traffic, a remote attacker can cause the browser to execute arbitrary code. The issue is identified as a CWE‑416 weakness and is capable of compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Google Chrome running on Linux is affected. No specific version numbers are published in the advisory; users should consult Google’s release notes for a fix or confirm that their installation is on a version newer than 149.0.7827.53 when released.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because it permits remote code execution via network traffic, the risk is considered high for systems that expose Chromoting or receive untrusted data. Until an official patch is available, malicious actors can exploit the flaw when the affected component is reachable over the network.
OpenCVE Enrichment