Impact
The vulnerability is a use‑after‑free flaw in the Views layer of Google Chrome. It allows an attacker who has already compromised the renderer process to execute code that bypasses Chrome’s site isolation safeguards. Based on the description of bypassing site isolation, it is inferred that the attacker could obtain or tamper with content from other sites, effectively breaking the isolation that protects distinct web origins. The weakness is classified as both CWE‑416 and CWE‑825.
Affected Systems
The flaw exists in Google Chrome versions prior to 148.0.7778.96. Users running those builds are affected regardless of operating system or architecture. The vulnerability can be triggered by loading a specially crafted HTML page into a compromised renderer instance.
Risk and Exploitability
The CVE has a CVSS score of 4.7, indicating moderate severity. Its EPSS score is < 1%, and it is not listed in the CISA KEV catalog, suggesting that it may not yet be widely exploited. However, the attack requires that the renderer process have already been compromised, which could happen through zero‑day exploitation of another Chrome weakness or through malicious extensions with high privileges. Based on the description, it is inferred that if a foothold in the renderer is achieved, the crafted HTML can be delivered remotely and the isolation bypass performed with low additional cost.
OpenCVE Enrichment
Debian DSA