Impact
Use after free vulnerability exists in the ServiceWorker module of Google Chrome prior to version 149.0.7827.103. The flaw allows an attacker who tricks a user into installing a malicious Chrome extension to read or write memory after the original allocation has been freed. In the worst case this can undermine the browser sandbox and give the attacker elevated privileges or control over the victim’s system.
Affected Systems
Google Chrome browsers running any build older than 149.0.7827.103 are affected. The issue is specifically tied to the Chrome ServiceWorker implementation and only impacts installations that allow the installation of third‑party extensions.
Risk and Exploitability
The weakness has a CVSS score of 8.3, classifying it as High by Chromium. No EPSS score is available and the vulnerability is not currently listed in CISA KEV, suggesting a lower public exploitation probability. However, the attack requires social engineering to install a malicious extension. If an attacker succeeds, sandbox escape could lead to full system compromise. Due to the lack of a published exploit, it is not known how often this vulnerability is being exploited in the wild.
OpenCVE Enrichment