Impact
A use‑after‑free flaw exists in the way Chrome extensions process data, allowing a remote attacker to trigger arbitrary code execution within a sandboxed process. The vulnerability, identified as a use after free (CWE-416), can be leveraged by an attacker who delivers a specially crafted HTML page to a user’s browser. This can lead to the execution of malicious code with the privileges of the sandboxed extension, potentially compromising the user’s data and system security.
Affected Systems
Google Chrome users running versions prior to 149.0.7827.53 are vulnerable. The issue affects the stable channel of Chrome and any installation that has not yet applied the update rolled out in June 2026.
Risk and Exploitability
The CVSS score of 8.8 marks this vulnerability as high severity, indicating a significant impact if exploited. An EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread, confirmed exploitation yet. The likely attack vector is remote, requiring a malicious web page to interact with the vulnerable extension, and an attacker would need the user to load that page while Chrome is running.
OpenCVE Enrichment