Impact
A use‑after‑free flaw in the Network component of Google Chrome allows a remote attacker to execute arbitrary code that runs inside the browser’s sandbox. The vulnerability is a classic CWE‑416 use‑after‑free, and also maps to CWE‑825. If exploited, the attacker can run attacker‑supplied code within the sandboxed process, potentially leading to privilege escalation within the user’s system through other browser vulnerabilities or side channels.
Affected Systems
All Google Chrome releases prior to 148.0.7778.216 are affected. The issue was fixed in the 148.0.7778.216 update and all later versions, regardless of operating system. Administrators should verify that their deployed Chrome instances use a version equal to or greater than 148.0.7778.216.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity, and the Chromium team labeled the flaw as Critical. The EPSS score is not available, so exploitation likelihood cannot be quantified, but the lack of a KEV listing suggests no widespread public exploitation as of now. The most probable attack vector is a malicious or compromised web page that, when loaded in the vulnerable browser, delivers a crafted payload that triggers the use‑after‑free and runs code inside the sandbox.
OpenCVE Enrichment