Impact
The vulnerability is a use‑after‑free flaw in Google Chrome’s FileSystem implementation. A maliciously crafted HTML page can trigger the flaw, causing heap corruption that may allow an attacker to execute arbitrary code or otherwise compromise the integrity of the system.
Affected Systems
Users of Google Chrome versions older than 149.0.7827.197 are affected. The defect is present in all Chrome builds before that release and was fixed in the 149.0.7827.197 update and subsequent ones.
Risk and Exploitability
Chromium labels the issue as High severity with a CVSS base score of 8.8. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so the precise exploitation probability is unknown. The stated attack vector involves a remote attacker delivering a crafted HTML page that a user opens; the exploit requires user interaction or a browser context that accesses the vulnerable FileSystem API. If successful, the heap corruption can lead to remote code execution on the victim’s machine.
OpenCVE Enrichment