Impact
A use‑after‑free vulnerability in the Mojo messaging framework of Google Chrome, identified as CWE‑416 and CWE‑825, permits a malicious HTML page to trigger undefined memory behavior. When exploited, the flaw can lead a remote attacker to escape the browser sandbox and execute code with higher privileges on the host operating system.
Affected Systems
All Google Chrome stable‑channel installations earlier than version 148.0.7778.168 on any operating system are affected. Users on the stable channel should ensure they have installed the latest update released by Google.
Risk and Exploitability
The CVE carries a CVSS score of 9.6, an EPSS score of less than 1%, and is not listed in CISA’s KEV catalog. Exploitation can be performed remotely via a crafted web page, after which the attacker may compromise the confidentiality and integrity of the operating system by breaking out of the sandbox. While no widespread exploitation has been reported at the time of this analysis, the high severity and remote nature of the attack vector warrant immediate attention.
OpenCVE Enrichment
Debian DSA