Impact
A use‑after‑free flaw exists in Chrome’s Ozone rendering engine that can corrupt heap memory and potentially allow a local attacker with physical access to execute arbitrary code or crash the browser. Based on the description, it is inferred that executing code is possible, though the advisory does not explicitly confirm this capability.
Affected Systems
Google Chrome versions that precede 149.0.7827.103 on any platform that uses the Ozone graphics stack are affected. Users running older releases of Chrome are potentially exposed to this flaw.
Risk and Exploitability
Chromium rates the issue as Critical, but the CVSS score of 6.8 indicates moderate overall severity. It requires local access and a user physically present at the device, limiting remote exploitation. No public exploits have been reported and the vulnerability is not included in the CISA KEV catalog. The EPSS score is not available, so the likelihood of exploitation remains uncertain, but the moderate severity indicates that administrators should prioritize applying the patch when local access can occur.
OpenCVE Enrichment