Impact
A use‑after‑free flaw in the V8 engine of Google Chrome can corrupt heap memory when a malicious Chrome extension is installed, potentially allowing an attacker to execute arbitrary code. The vulnerability arises after an object is freed while references still exist, violating memory safety. Based on the description, it is inferred that the resulting heap corruption could be leveraged to run attacker‑supplied code.
Affected Systems
Google Chrome users running any desktop version prior to 147.0.7727.55 on Windows, macOS or Linux are affected, because the V8 JavaScript engine is included with the browser on all those platforms.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk, yet the EPSS score below 1% reflects a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to first install a malicious extension, so the likely attack vector is social engineering rather than an automated network attack.
OpenCVE Enrichment
Debian DSA