Impact
The vulnerability is a use‑after‑free flaw in the V8 JavaScript engine that allows an attacker to craft a malicious Chrome extension. When the user installs and runs the extension, the flaw enables the attacker to execute arbitrary code inside Chrome’s sandbox. This flaw is identified as CWE‑416.
Affected Systems
Google Chrome versions earlier than 148.0.7778.96 are affected. The issue is specific to the Desktop Chrome stable channel and applies to all platforms where that version is installed.
Risk and Exploitability
The flaw was assigned Chromium security severity Medium, but the CVSS score of 8.8 indicates high severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires social engineering to convince a user to install a malicious extension; once the extension is installed the code runs with sandboxed privileges. The risk is mitigated by applying the Chrome patch and by restricting the installation of extensions.
OpenCVE Enrichment
Debian DSA