Impact
Use after free in Web Apps in Google Chrome before version 149.0.7827.103 leads to a sandbox escape when a remote attacker has already compromised the renderer process. The vulnerability allows the attacker to execute code in a privileged context by serving a crafted HTML page, effectively bypassing browser sandbox restrictions and potentially compromising the operating system.
Affected Systems
Google Chrome desktop browsers on all supported platforms, versions earlier than 149.0.7827.103.
Risk and Exploitability
The vulnerability is rated critical in Chromium security. No EPSS score is available and it is not listed in the CISA KEV catalog. Exploitation requires control over the renderer process and delivery of a malicious HTML payload, making successful attacks more complex but still plausible if the renderer is compromised. The CVSS score is 8.3, indicating a high severity level and a significant potential impact if exploited.
OpenCVE Enrichment