Impact
Google Chrome versions prior to 149.0.7827.103 contain a use-after-free vulnerability in the Proxy component that allows a remote attacker to execute arbitrary code. The flaw is a classic memory safety issue (CWE-416), where invalid memory use can lead to code execution, jeopardizing confidentiality, integrity, and availability of the affected system. The problem is a severe security weakness classified by Chromium as Critical.
Affected Systems
Affected vendor is Google, product Chrome, specifically any desktop builds older than version 149.0.7827.103. If the installation does not include the latest update, the system is exploitable.
Risk and Exploitability
The lack of an EPSS score indicates no publicly available exploitation probability data, but the CVSS score of 8.1 and Remote Code Execution impact create high risk. Because the vulnerability is triggered by malicious network traffic, an attacker can deliver crafted data over the network to trigger the use-after-free during proxy processing. This attack leverages remote access, so the potential impact is system-wide. No KEV listing is present, but the high severity warrants urgent mitigation.
OpenCVE Enrichment