Impact
A use‑after‑free flaw in Aura of Google Chrome on Windows allows a remote attacker who has compromised a renderer process to escape the browser sandbox and potentially execute arbitrary code. The weakness is a use‑after‑free in memory management (CWE‑416), and because the renderer runs with limited privileges, a successful attack would give the attacker full system access.
Affected Systems
The vulnerability affects all Windows deployments of Google Chrome versions earlier than 148.0.7778.96. Users browsing malicious web pages with these outdated builds are exposed until the update is applied.
Risk and Exploitability
The EPSS score is not available and the issue is not yet listed in CISA KEV; the CVSS score of 8.3 indicates high severity. Attackers must deliver crafted HTML to a victim’s browser, which is a typical web‑based exploitation path. Once the renderer is involved, the use‑after‑free can trigger a sandbox escape, enabling full remote code execution on the host.
OpenCVE Enrichment