Impact
The vulnerability is a use‑after‑free bug in the XR (extended‑reality) component of Google Chrome on Windows. When a malicious HTML page is loaded, the browser may dereference memory that has already been freed, allowing a remote attacker to execute arbitrary code with the privileges of the user who opens the page. This flaw is a classic Use‑After‑Free weakness (CWE‑416) and is classified as high severity.
Affected Systems
Windows users running any Google Chrome version earlier than 148.0.7778.179 are affected. The issue was tracked in Chromium issue 498702233 and was fixed in the stable‑channel update released on 2026‑05‑08. Build versions on the stable channel older than that may still be vulnerable, while newer stable releases and other channels are not impacted.
Risk and Exploitability
The CVSS score of 8.8 signals a high‑severity flaw, and the EPSS score of <1% indicates that exploitation is currently unlikely, though not impossible. The vulnerability is not listed in the CISA KEV catalog, so no public exploit has been documented as of the time of this analysis. Because the flaw is triggered by a crafted web page, an attacker must obtain a victim’s browsing activity; the potential for widespread impact remains, but the probability of a successful exploit is modest.
OpenCVE Enrichment
Debian DSA