Impact
A use‑after‑free bug in Blink, the rendering engine of Google Chrome, allows a heap corruption condition to be triggered by a crafted HTML page. The vulnerability is rated high severity and can lead to arbitrary code execution if successfully exploited.
Affected Systems
Users running Google Chrome versions prior to 146.0.7680.153 on any operating system, including Windows, macOS, and Linux, are affected. The issue does not affect other browsers or Chrome extensions directly.
Risk and Exploitability
The CVSS score of 8.8 indicates a substantial risk, and the EPSS score of less than 1% suggests that exploitation is currently uncommon. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is a remote attacker delivering malicious HTML content that triggers the use‑after‑free while the browser is rendering the page, compromising the browser process and potentially the system.
OpenCVE Enrichment
Debian DSA