Impact
A use‑after‑free flaw in Chrome’s TabStrip component can trigger arbitrary code execution when a user loads a crafted web page and performs specific UI gestures. The vulnerability is classified as critical.
Affected Systems
Google Chrome versions earlier than 149.0.7827.103 on desktop environments are impacted.
Risk and Exploitability
The vulnerability does not appear in the KEV catalog and has an EPSS score of < 1%, indicating a very low probability of exploitation. The CVSS score of 7.5 indicates high severity. Exploitation requires an attacker to convince a user to visit a crafted web page and perform specific UI interactions, indicating a social‑engineering component. Once triggered, the exploit would allow attacker control over the affected process and potentially unauthorized code execution on the user’s machine.
OpenCVE Enrichment
Debian DSA