Impact
The vulnerability is a use‑after‑free flaw in the Gamepad implementation within Google Chrome. It permits a crafted HTML page to trigger a memory error that can escape the browser sandbox. If successful, an attacker could gain the ability to execute arbitrary code with the privileges of the Chrome process, potentially compromising the host system.
Affected Systems
All Windows installations of Google Chrome prior to version 149.0.7827.103 are susceptible. Users running older stable releases are at risk.
Risk and Exploitability
The flaw’s severity is 9.6 on the CVSS scale, which corresponds to Critical. No EPSS score is currently available, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is an HTTP(S) site delivering a malicious page that leverages the Gamepad API. Attack execution would require the user to open the crafted page in Chrome on a Windows machine. With the sandbox escaped, the attacker could perform actions beyond the browser’s protection boundaries.
OpenCVE Enrichment