Impact
A use‑after‑free flaw in the Tracing component of Google Chrome can be triggered by a crafted HTML page if a renderer process has been compromised. This error arises from a misuse of tracing APIs, leading to a memory corruption that violates the sandbox model (CWE‑416) and also reflects a failure in handling error results from the tracing interface (CWE‑825). The flaw may allow a remote attacker to escape the sandbox that normally isolates tab content, potentially granting higher privilege code execution.
Affected Systems
Google Chrome versions prior to 149.0.7827.103 are affected across all supported platforms. The vulnerability resides in the Tracing component of Chrome's core browser code.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low but non-zero probability of exploitation. The CVSS score of 8.3 reflects a high severity level. The flaw requires an attacker to have already compromised the renderer process, typically via malicious web content, which then can trigger the use‑after‑free and potentially escape the sandbox. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA