Impact
A use‑after‑free flaw in Chrome’s GPU code lets a malicious renderer process corrupt heap memory when it parses a specially crafted web page. The vulnerability may enable heap corruption via crafted HTML, as described in the CVE. The flaw corresponds to CWE‑416 and CWE‑825, involving improper use of freed memory after the owning object has been released and other mismanagement of internal memory structures.
Affected Systems
The flaw affects Google Chrome versions older than 147.0.7727.138 across all desktop platforms. Versions prior to this release are vulnerable; newer releases include the repair.
Risk and Exploitability
The CVSS score is 7.5, the EPSS score is < 1%, and it is not listed in CISA’s KEV catalog. The attack requires an attacker to have already compromised the renderer process, which is typically achieved via a malicious web page; thus the likely vector is remote through crafted content. Given the potential for heap corruption, the risk remains significant until a patched version is deployed.
OpenCVE Enrichment
Debian DSA