Impact
A use-after-free flaw exists in Chrome’s Network code for versions before 149.0.7827.115. The flaw allows an attacker positioned on a privileged network to send specially crafted traffic that corrupts heap memory, potentially enabling arbitrary code execution. The vulnerability is categorized as a high‑severity issue by Chromium’s own security team.
Affected Systems
Google Chrome versions older than 149.0.7827.115 on all supported operating systems are vulnerable. No specific environment restrictions are listed, but the attacker must be able to dictate network traffic to the target.
Risk and Exploitability
The flaw’s high severity rating combined with the use‑after‑free nature suggests a serious exploitation risk, although the EPSS score is currently unavailable and the vulnerability is not listed in CISA’s KEV catalog. Exploitation likely requires a trusted network segment or an attacker with sufficient privileges to generate malicious traffic toward the victim’s Chrome instance.
OpenCVE Enrichment