Impact
Use‑after‑free vulnerability in the Network component of Google Chrome allows a remote attacker who has already compromised the renderer process to read arbitrary memory, potentially exposing sensitive data. The weakness is a classic Use‑after‑free error (CWE‑416) and also involves improper resource management (CWE‑825) that can enable unauthorized data disclosure.
Affected Systems
Affects Google Chrome browsers running versions earlier than 149.0.7827.53. The issue is present in all default channels that include these legacy releases. Users of these versions are at risk when they load malicious or crafted web content while the renderer process has been compromised.
Risk and Exploitability
The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited observed exploitation. The CVSS score of 4.7 reflects a moderate severity, matching the low Chromium severity, and indicates that the damage window is modest. Exploitation requires the attacker to first gain the renderer process, then deliver a crafted HTML page; the attack surface is therefore constrained to environments that have already been breached at the renderer level.
OpenCVE Enrichment
Debian DSA