Impact
Use after free in the TabStrip class of Google Chrome before version 149.0.7827.53 allows an attacker to cause arbitrary code execution by delivering a crafted HTML document. The flaw occurs when a memory object is accessed after deallocation, enabling the attacker to influence subsequent memory usage. While the Chromium project rates the bug as low severity, the CVSS score of 8.8 signifies that the vulnerability could lead to full system compromise, including loss of confidentiality, integrity, and availability.
Affected Systems
All Google Chrome installations on Windows, macOS, Linux, and Chrome OS running versions older than 149.0.7827.53 are affected.
Risk and Exploitability
The flaw can be triggered remotely by simply opening a malicious webpage in the vulnerable browser. With a CVSS score of 8.8 the risk is high, yet the EPSS of less than 1% and absence from the CISA KEV catalog indicate a low likelihood of exploitation in the wild. However, if an attacker succeeds, the use‑after‑free bug permits complete remote code execution on the target machine.
OpenCVE Enrichment
Debian DSA