Impact
The vulnerability is a use‑after‑free flaw in Google Chrome’s ReadingMode feature. It permits an attacker who can influence the renderer process, likely by supplying malicious web content, to trigger code execution inside a sandboxed renderer by loading a specially crafted HTML page. Success would give the attacker arbitrary code execution within the renderer sandbox, likely allowing further privilege escalation through known sandbox escape techniques. The weakness is identified as CWE‑416.
Affected Systems
Google Chrome browsers prior to version 148.0.7778.96 are affected. Users running the stable channel of Chrome below this version should verify their install against the latest release.
Risk and Exploitability
The flaw carries a high severity rating according to its CVSS score of 8.8. Attackers would need to compromise the renderer process, likely by supplying malicious web content. No publicly known exploits are listed in the CISA KEV catalog and the EPSS score is unavailable, indicating uncertainty about the exploitation probability. Nonetheless, the presence of a use‑after‑free bug that leads to code execution warrants prompt attention.
OpenCVE Enrichment
Debian DSA