Impact
The vulnerability is a Use After Free in the DigitalCredentials component of Google Chrome. When a remote attacker compromises the renderer process – for example by delivering a specially crafted HTML page – the freed memory can be accessed, enabling a sandbox escape and potentially allowing code execution beyond the browser’s confined environment. The attacker could thereby read, modify, or exfiltrate data from the host system, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
All desktop installations of Google Chrome running a version prior to 149.0.7827.115 are impacted. The issue exists in the stable channel of Chrome and affects every operating system where this version is deployed.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack requires the attacker to first gain control of the renderer process via a malicious web page, which is a remote attack vector. Due to the high severity and the potential for sandbox escape, the overall risk to systems running vulnerable Chrome versions is significant.
OpenCVE Enrichment