Impact
The vulnerability is a use‑after‑free in the Agents component of Google Chrome, allowing a maliciously crafted HTML page to corrupt the browser heap. This corruption can give a remote attacker the ability to execute arbitrary code, thereby compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
Google Chrome versions prior to 146.0.7680.71 across Windows, macOS, Linux, and other operating systems that run Chrome are affected. The flaw resides within Chrome’s rendering engine and is not limited to a specific OS.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating a high severity. Its EPSS score is less than 1 % and it is not listed in the CISA KEV catalog, suggesting low current exploitation probability but still high impact if discovered. The attack vector is likely a web page served over the Internet that triggers the bug while the user renders it in Chrome; the attacker does not need elevated privileges or physical access. Exploitation relies on heap corruption, which is well understood by adversaries, so once the patch is known, the exploit could be mounted in the wild.
OpenCVE Enrichment
Debian DSA