Impact
A use‑after‑free flaw located in the Navigation component of Google Chrome versions prior to 147.0.7727.138 allows an attacker to execute arbitrary code by serving a malicious HTML page. The weakness permits arbitrary memory access, enabling a remote attacker to compromise the confidentiality, integrity, and availability of the system by running code with the privileges of the Chrome process.
Affected Systems
All users of Google Chrome running any release before 147.0.7727.138 are affected. The vulnerability exists in the core navigation stack used by the browser to load web pages, and no specific operating system or architecture limitation is reported.
Risk and Exploitability
The event is a high‑severity flaw that can be triggered when a user opens or renders a crafted HTML document. No publicly available exploit code is listed, and the EPSS score is not yet available, but the absence from CISA’s KEV catalog does not diminish the potential for widespread exploitation. Attackers can achieve remote code execution simply by hosting the malicious page and enticing a victim to visit it, making the vulnerability highly actionable and presenting a significant risk to all affected users.
OpenCVE Enrichment