Impact
The vulnerability is a use‑after‑free bug in Chrome’s GPU image‑buffer handling that can be triggered by a malicious HTML page. When the renderer processes such a page, a reference to a freed buffer can be reused, potentially breaking out of the renderer sandbox and giving an attacker code execution privileges.
Affected Systems
Google Chrome for desktop is affected. All stable releases prior to version 147.0.7727.138 contain the vulnerability in the GPU component of the renderer process.
Risk and Exploitability
Chromium labels the issue as High severity; the EPSS score is not publicly available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious webpage that causes the browser to re‑use GPU memory, so an attacker who can host or inject content into a user’s browsing session could exploit the bug. Successful exploitation could lead to a sandbox escape and full system compromise. The risk is significant because the attack requires only a crafted page, making it potentially wide‑scale if distributed via compromised sites or phishing emails.
OpenCVE Enrichment