Impact
The vulnerability is a use–after–free flaw located in the Tab Groups feature of Google Chrome. The flaw allows a remote attacker to trigger arbitrary code execution by sending specially crafted network traffic to a vulnerable Chrome instance. The underlying weakness corresponds to CWE-416 and the misuse of stale or corrupted memory characteristic of CWE-825, and it is evaluated by Chromium as critical severity.
Affected Systems
Google Chrome browsers prior to version 148.0.7778.168 on the desktop stable channel are affected. The issue does not specify any particular operating systems but applies to all platforms for which the desktop stable channel is available.
Risk and Exploitability
The flaw can be exploited remotely via malicious network traffic, requiring only an attacker capable of delivering such traffic to the victim machine. The EPSS score is < 1%, indicating a very low overall exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. A CVSS score of 7.5 denotes high severity, and the remote nature of the attack vector implies a serious risk to affected systems.
OpenCVE Enrichment
Debian DSA