Impact
In Google Chrome versions prior to 149.0.7827.103, the V8 engine contains a use‑after‑free bug that allows a remote attacker to deliver a crafted HTML page that causes the renderer to execute arbitrary code inside the browser's sandbox. This vulnerability is categorized as CWE‑416, a misuse of a freed pointer that can lead to code execution. The consequence is that any user who visits a malicious page in an affected Chrome instance could run code within the sandboxed environment, potentially escalating privileges or accessing sensitive data if the sandbox is breached.
Affected Systems
The issue affects Google Chrome browsers on all platforms that run versions earlier than 149.0.7827.103. Users of these older Chrome releases are vulnerable regardless of operating system because the flaw is present in the V8 engine component shared across Chrome builds.
Risk and Exploitability
The exploit requires a web page crafted by an attacker and the victim must open this page in an impacted Chrome browser. No public exploit class is documented and EPSS is not available, but the vulnerability is given a high rating by Chromium which indicates that it is actionable. The CVE is not listed in CISA's KEV catalog, and no official workaround exists, so the primary mitigation is to patch the browser.
OpenCVE Enrichment