Impact
The vulnerability involves a use‑after‑free in the WebShare component of Google Chrome on Windows. If a renderer process is compromised, an attacker can construct a malicious HTML page that triggers the freed memory use, potentially allowing the attacker to escape the renderer sandbox and execute arbitrary code with elevated privileges. This weakness is classified as CWE‑416 and is rated critical by Chromium security.
Affected Systems
Systems running Google Chrome on Windows with a version older than 149.0.7827.155 are impacted. The vulnerability was present in all prior stable releases before the security release on 2026‑06‑17 that fixed the WebShare use‑after‑free.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity, but the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not recorded in the CISA KEV catalog, suggesting no widespread exploitation yet. Based on the description, it is inferred that the likely attack vector is a local attacker who can serve a crafted HTML page to the renderer process, so the risk is significant for internal users or applications that allow untrusted HTML content.
OpenCVE Enrichment