Impact
Use after free in the TabStrip class of Google Chrome before 149.0.7827.53 allows a remote attacker to execute arbitrary code by serving a crafted HTML page. The flaw arises from an object being accessed after it has been freed, enabling the attacker to control memory references and trigger code execution. While the Chromium project rates this issue as low severity, the potential impact is full compromise of the user’s system, including integrity and confidentiality loss.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 on Windows, macOS, Linux, or Chrome OS are affected.
Risk and Exploitability
The vulnerability can be exploited over the network by opening a malicious webpage in the browser. The EPSS score is not reported and it is not listed in the CISA KEV catalog, implying limited public exploitation data. However, the nature of a use‑after‑free bug can allow complete remote code execution if an attacker can host the crafted page and entice an end‑user to visit it.
OpenCVE Enrichment