Impact
This vulnerability is a use‑after‑free flaw (CWE‑416) and an additional flaw related to execution control (CWE‑825) in the V8 JavaScript engine of Google Chrome. A crafted HTML page can trigger the flaw, allowing a remote attacker to execute arbitrary code within the sandboxed browser process. The size of the impact is high because the attacker gains code execution without additional privileges, potentially compromising the user's data and browsing session.
Affected Systems
All desktop editions of Google Chrome released prior to version 149.0.7827.103 are affected. This includes Windows, macOS, and Linux builds that run the V8 engine in the browser.
Risk and Exploitability
Exploitation requires only that a user visit a malicious web page; no additional credentials are needed. The code runs inside the browser sandbox, limiting direct system access but still allowing for session hijacking and potential pivot to higher privileged processes. The CVSS score of 8.8 denotes high severity. The EPSS score of 0.00128 indicates a very low, but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but the combination of high score and remote exposure warrants immediate attention.
OpenCVE Enrichment
Debian DSA