Impact
A use-after-free flaw in Chrome’s Tab Strip module allows a crafted HTML page to trigger heap corruption. The vulnerability can be triggered when a user performs specific UI gestures, potentially enabling a malicious actor to execute arbitrary code in the browser’s process. The weakness is identified as a classic memory corruption issue (CWE‑416).
Affected Systems
Google Chrome browsers before version 149.0.7827.155 on desktop are affected. Users who have not upgraded to the latest stable channel release are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the EPSS score of less than 1% shows the exploitation likelihood is very low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, through a malicious web page that a user must open and interact with, and it requires the user to perform certain UI gestures to trigger the heap corruption.
OpenCVE Enrichment