Impact
A use-after-free flaw in Google Chrome’s InterestGroups implementation permits an attacker to execute arbitrary code inside the browser’s sandbox when a crafted HTML page is opened. The vulnerability exists in Chrome versions prior to 149.0.7827.103 and is classified as high severity. It does not allow direct access outside the sandbox, but it does enable arbitrary code to run with the privileges of the browser process.
Affected Systems
All users running Google Chrome for desktop on any supported operating system with a version earlier than 149.0.7827.103 are affected. The vulnerability is present in the Chromium source used to build the stable channel of Chrome.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the lack of an EPSS score suggests that no current data is available about exploit prevalence. The flaw is not listed in the CISA KEV catalog and no public exploits have been reported. Exploitation requires an attacker to deliver a malicious HTML page to a user, after which the use-after-free can be triggered to run code within the browser sandbox.
OpenCVE Enrichment