Impact
Google Chrome versions older than 147.0.7727.101 contain a use‑after‑free flaw in the FileSystem module, identified as CWE‑416. The vulnerability arises when a maliciously crafted HTML page is rendered, allowing the browser to read or write to a memory object that has already been freed, potentially leading to object corruption. This issue also involves improper bounds checking, corresponding to CWE‑825. Based on the description, it is inferred that the corruption could result in unintended behavior, including possible code execution if an exploit chain is executed.
Affected Systems
The flaw affects all installations of Google Chrome on every platform when the installed version is earlier than 147.0.7727.101, regardless of operating system.
Risk and Exploitability
The vulnerability carries a high severity rating, with a CVSS score of 8.8. The likelihood of exploitation in the wild is very low, and it is not listed among publicly known exploited vulnerabilities. Attackers can deliver the crafted HTML page remotely through normal web content, triggering the use‑after‑free without requiring additional privileges. Successful exploitation would depend on additional conditions such as the presence of other vulnerabilities and host configuration.
OpenCVE Enrichment
Debian DSA