Impact
A use‑after‑free flaw exists in the Dawn rendering engine of Google Chrome, which allows an attacker who has already compromised the renderer process to run arbitrary code. The vulnerability is triggered by a specially crafted HTML page and is classified as high severity in Chromium’s own ranking.
Affected Systems
The flaw affects Google Chrome versions prior to 146.0.7680.178. It is present on all major operating systems supported by Chrome, including macOS, Linux, and Windows, as the vulnerability resides in the shared rendering component rather than a platform‑specific module.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact if exploited, but the EPSS score of less than 1% suggests a low expected exploitation rate. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker can influence or already control the renderer process, which is generally isolated from the main browser process, so while the potential damage is significant, the likelihood of a real‑world attack remains modest.
OpenCVE Enrichment
Debian DSA