Impact
The vulnerability is a use‑after‑free in the GTK component used by Chrome on Windows, which can be triggered by a crafted HTML page. An attacker who lures a user to view that page can cause the browser to execute arbitrary code. This flaw is classified as high severity by the Chromium security review and falls under CWE‑416 and CWE‑825, indicating memory‑management defects that enable arbitrary code execution when a dangling pointer is dereferenced or security checks are inadequately imposed.
Affected Systems
Google Chrome running on Windows is affected; all installations of Chrome prior to version 148.0.7778.168 are vulnerable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 8.8 indicates high severity and the remote trigger through a web page imply a significant risk to users who open untrusted or malicious HTML content. The attack vector is remote and requires only a crafted page delivered over the Internet or locally. Without a patch, an attacker can achieve full arbitrary code execution on the victim’s machine.
OpenCVE Enrichment
Debian DSA