Impact
A use‑after‑free flaw exists in the Canvas implementation of Google Chrome on Linux and ChromeOS versions prior to 147.0.7727.138. The vulnerability permits a remote attacker to craft a malicious HTML page that, when opened by a victim, causes the browser to execute arbitrary code inside its sandboxed rendering process. The flaw is classified by Chromium as Critical and is identified as CWE-416. The attacker can potentially redirect execution flow to injected code, thereby compromising the sandboxed context of the browser.
Affected Systems
Google Chrome on Linux and ChromeOS systems using versions earlier than 147.0.7727.138 are affected. The Canvas feature in these versions contains the vulnerable memory handling bug. No other products are listed as affected.
Risk and Exploitability
The EPSS score is not available, and the vulnerability has not been listed in CISA's KEV catalog. However, the Critical severity designation from Chromium indicates a high likelihood of exploitation in the wild. The attack vector is remote, relying on a crafted HTML page that a user can be induced to open, such as via a malicious website or phishing email. Once triggered, the flaw allows execution of arbitrary code within the browser's sandbox, providing a foothold for further attacks.
OpenCVE Enrichment