Impact
A use-after-free vulnerability was found in the Views component of Google Chrome on Windows before version 149.0.7827.103. This flaw allows an attacker who has already compromised a renderer process to craft a malicious HTML page that can trigger a sandbox escape, potentially giving the attacker arbitrary code execution outside the browser’s sandbox. The weakness is categorized as CWE‑416 and has a Chromium security severity of high.
Affected Systems
Google Chrome running on Windows systems prior to the 149.0.7827.103 release are affected. Users of older Chrome builds should verify the revision of the browser and consider upgrading.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, and with no EPSS score available and not listed in the CISA KEV catalog, the threat remains serious. Attackers would need to first compromise the renderer process, which is typically achieved through a malicious web page or an untrusted content source, then exploit the use-after-free to break out of the sandbox. Without the needed renderer compromise, exploitation is unlikely, but once that condition is met, the impact could be complete system compromise.
OpenCVE Enrichment