Impact
A use–after–free flaw exists in the DigitalCredentials component of Google Chrome on Windows versions before 149.0.7827.155. The flaw, classified as CWE‑416, allows a maliciously crafted HTML page to be executed by a remote attacker, potentially resulting in sandbox escape and unauthorized code execution. The impact is a loss of both confidentiality and integrity of the user’s data. Because the vulnerability originates from improper memory handling, it can be leveraged to compromise the entire system.
Affected Systems
The vulnerability affects all Windows installations of Google Chrome that are running a pre‑149.0.7827.155 build. Users of the latest stable channel or any newer revision are not impacted. No other platforms or browsers are listed as affected.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity, while the EPSS score of less than 1% suggests the probability of a publicly available exploit is currently low. The vulnerability is not listed in CISA’s KEV catalog, so no known exploitation campaigns have been reported yet. Attackers would need to deliver a crafted HTML page to a user, likely via a compromised website or phishing email. The path then involves triggering the use‑after‑free in an unsecured memory context, leading to sandbox escape and further exploitation.
OpenCVE Enrichment