Impact
A use‑after‑free vulnerability exists in Google Chrome’s File Input handling that can be triggered by a crafted HTML page, allowing a remote attacker to corrupt the heap and potentially execute arbitrary code. The flaw originates from improper memory management and is listed in Chromium as a Critical severity issue.
Affected Systems
Google Chrome versions prior to 149.0.7827.103 are affected. No specific patch level is available beyond the newest stable release at the time of this advisory.
Risk and Exploitability
The vulnerability is exploitable from a web page and could enable remote code execution. The CVSS score of 8.8 indicates high severity. Although the EPSS score is not available and the issue is not in the CISA KEV list, the critical severity assigned by Chromium indicates a high likelihood of exploitation in the wild. The attack surface is a remote HTML page loaded by an affected Chrome browser.
OpenCVE Enrichment