Impact
A type confusion bug in the CSS engine of Chrome allows an attacker who persuades a user to install a malicious extension to corrupt the heap. The heap corruption could be leveraged to execute arbitrary code if the attacker controls the crafted content. The weakness is identified as CWE-843, reflecting type confusion in typically trusted browser components.
Affected Systems
Google Chrome on all supported platforms is affected. The vulnerability exists in all builds prior to version 147.0.7727.55. Users on Windows, macOS, Linux, or other operating systems that run these Chrome versions should be aware of the risk.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% suggests that the likelihood of current exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the user to install a malicious extension, so an attacker would rely on social engineering to convince the victim to install the extension. Once installed, the extension could trigger the heap corruption and lead to code execution.
OpenCVE Enrichment
Debian DSA