Impact
Chrome extensions that use a renderer process are susceptible to a use‑after‑free flaw (CWE-416) and an access to uninitialized memory flaw (CWE-825). An attacker who has already compromised the renderer can trigger the free memory reuse, enabling a sandbox escape and execution of arbitrary code. The vulnerability is categorized by Chromium as High severity. Because the flaw allows execution of code outside the browser sandbox, it can potentially expose sensitive system data and compromise host integrity.
Affected Systems
All users of Google Chrome on the desktop whose browsers are below version 149.0.7827.103 are affected. The problem was fixed in the 149.0.7827.103 release announced in early June 2026.
Risk and Exploitability
Risk is high. The CVSS score of 8.3 indicates a major severity, while the EPSS score of < 1% shows a very low generic exploitation probability. Although exploitation requires an attacker who has already compromised the renderer process—likely through a malicious extension or compromised web page—the flaw provides a path to sandbox escape and remote code execution. The vulnerability is not listed in CISA’s KEV catalog, so no publicly known exploits are reported yet; however, the low EPSS score does not eliminate the possibility of targeted attacks leveraging this flaw.
OpenCVE Enrichment
Debian DSA