Impact
The vulnerability is a use‑after‑free flaw in the codecs component of Google Chrome that allows a maliciously crafted HTML page to trigger a memory error inside the browser process. This flaw, identified as CWE‑416, can lead to the execution of arbitrary code while the browser runs in its sandboxed environment and could compromise the confidentiality, integrity, and availability of the user’s data. The issue is also classified as CWE‑825, indicating an additional weakness that may contribute to or compound the exploitability.
Affected Systems
Google Chrome versions earlier than 147.0.7727.101 are affected. The issue exists on all supported operating systems until the user updates to this release or a newer one.
Risk and Exploitability
The likely attack vector is a remote web‑based delivery of a specially crafted HTML page. The CVSS score of 9.6 classifies this flaw as critical, and EPSS is not available, indicating uncertain but potentially low exploitation probability. The vulnerability offers a native code execution path that could be leveraged by an adversary to compromise the browser sandbox and potentially pivot to other system resources. KEV does not list this vulnerability. Although no current exploitation reports exist, the high severity warrants immediate mitigation.
OpenCVE Enrichment