Impact
The vulnerability is a use‑after‑free flaw in the ServiceWorker implementation of Google Chrome that allows an attacker who has already compromised the renderer process to execute arbitrary code inside the browser’s sandbox. This flaw is identified as CWE-416 and CWE-825 and can result in arbitrary code execution, potentially giving an attacker control over the affected system. The impact is limited to the sandboxed environment of the renderer but can be leveraged by a suitably privileged attacker to perform further lateral movement.
Affected Systems
Google Chrome versions earlier than 149.0.7827.103 are affected. Any user running a vulnerable version on any supported operating system is at risk if a malicious crafted web page is loaded in the compromised renderer process.
Risk and Exploitability
The CVSS score of 7.5 indicates High severity. Exploitation requires a prior compromise of the renderer process and a crafted HTML page, implying a complex attack vector that is not typical of public exploits. The EPSS score indicates a very low probability of exploitation (less than 1%) and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. Nevertheless, the potential for remote code execution in a sandboxed environment presents a significant risk to users running outdated Chrome versions.
OpenCVE Enrichment
Debian DSA