Impact
A use‑after‑free flaw in Chrome’s GPU code lets a malicious renderer process corrupt heap memory when it parses a specially crafted web page. The vulnerability can allow an attacker with control over the renderer to cause undefined behaviour that may lead to arbitrarily memory corruption, potentially enabling code execution or denial of service. The weakness corresponds to CWE‑416, involving improper use of freed memory after the owning object has been released.
Affected Systems
The flaw affects Google Chrome versions older than 147.0.7727.138 across all desktop platforms. Versions prior to this release are vulnerable; newer releases include the repair.
Risk and Exploitability
The issue has a high severity assessment, but no EPSS score is available and it is not listed in CISA’s KEV catalog. The attack requires an attacker to have already compromised the renderer process, which is typically achieved via a malicious web page; thus the likely vector is remote through crafted content. Given the potential for arbitrary heap corruption, the risk remains significant until a patched version is deployed.
OpenCVE Enrichment