Impact
A use‑after‑free vulnerability exists in the CSS parser of Google Chrome prior to version 145.0.7632.75. This is a CWE‑416: Use After Free flaw. The vulnerability occurs when the browser releases memory that is later accessed while parsing CSS, allowing an attacker to execute arbitrary code in the sandboxed browser process. The execution is confined to the sandbox; launching attacks beyond the sandbox requires additional weaknesses.
Affected Systems
Google Chrome installations running any version earlier than 145.0.7632.75 are affected. Based on the known CPEs, it is inferred that this includes Microsoft Windows, macOS, and Linux platforms. Users who load malicious web pages rendered by those browsers are at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, and its EPSS score of 55 % indicates a high likelihood of exploitation. The vulnerability is listed in the CISA KEV catalog, confirming that attacks have been observed. Based on the description, the likely attack vector is remote via a crafted HTML page that triggers the CSS parser. Because the code runs inside the Chrome sandbox, the impact is limited to the browser process itself, but it can affect the confidentiality and integrity of data processed by the browser.
OpenCVE Enrichment
Debian DSA