Impact
Google Chrome is vulnerable to a use‑after‑free condition within its Web Authentication component. This flaw, classified as CWE‑416, allows an attacker to craft a malicious HTML page that forces Chrome to execute memory that has already been freed, resulting in arbitrary code execution on the victim’s machine. The vulnerability carries a Chromium security severity of Critical and permits full control over the affected system once the victim opens the malicious page.
Affected Systems
All desktop installations of Google Chrome running a version earlier than 149.0.7827.155 are impacted. Devices that have not updated to the latest stable release are susceptible to exploitation.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity risk, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild at this time. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is a web‑based attack that requires a victim to load a malicious page in Chrome, after which arbitrary code can be injected and executed.
OpenCVE Enrichment