Impact
The vulnerability is a use‑after‑free bug in the GPU component of Google Chrome before version 148.0.7778.96. When a remote attacker can compromise the renderer process, a specially crafted HTML page can trigger the bug, allowing the attacker to escape the renderer sandbox and execute code with higher privileges.
Affected Systems
All machines running Google Chrome earlier than 148.0.7778.96 on any supported operating system with GPU acceleration enabled are affected. No specific operating‑system limitation is mentioned, so any platform that runs the vulnerable Chrome version is at risk.
Risk and Exploitability
The CVE has a CVSS score of 8.3, EPSS data is unavailable, and it is not listed in the CISA KEV catalog. The attack vector requires a compromised renderer process, which is typically achieved by a user visiting malicious web content. Successful exploitation could lead to sandbox escape and local code execution, potentially enabling further attacks. Given the prevalence of Chrome and the ease of delivering a crafted web page, the risk remains significant until a patch is applied.
OpenCVE Enrichment
Debian DSA