Impact
A use‑after‑free bug in the Dawn rendering engine of Google Chrome (prior to version 146.0.7680.178) allows a remote attacker to run arbitrary code by delivering a crafted HTML page. The vulnerability is a classic memory safety flaw (CWE‑416) where a freed object is accessed, potentially leading to code execution, data disclosure, or denial‑of‑service.
Affected Systems
The flaw affects all platforms where Chrome is available—Windows, macOS, and Linux—prior to the 146.0.7680.178 release. The affected product is the Google Chrome browser, reachable through the stable channel for desktop users.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is considered high severity. The EPSS score is below 1 % and it is not listed in CISA’s KEV catalog, suggesting a low current exploitation probability. The likely attack vector is delivery of malicious HTML via phishing, drive‑by sites, or other web‑based channels. Successful exploitation would grant the attacker remote code execution on the victim’s machine.
OpenCVE Enrichment
Debian DSA