Impact
Use-after-free vulnerability in the Network component of Google Chrome allows a remote attacker who has already compromised the renderer process to read arbitrary memory, potentially exposing sensitive data. The weakness is a classic Use-after-free error (CWE-416) that enables unauthorized data disclosure.
Affected Systems
Affects Google Chrome browsers running versions earlier than 149.0.7827.53. The issue is present in all default channels that include these legacy releases. Users of these versions are at risk when they load malicious or crafted web content while the renderer process has been compromised.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited observed exploitation. However the CVE’s low Chromium severity indicates that the damage window is modest. Exploitation requires the attacker to first gain the renderer process, then deliver a crafted HTML page; the attack surface is therefore constrained to environments that have already been breached at the renderer level.
OpenCVE Enrichment