Impact
A use‑after‑free condition was identified in the Dawn graphics engine of Google Chrome. The flaw allows a remote attacker to load a specially crafted HTML page that can trigger a sandbox escape, potentially giving the attacker elevated privileges on the host system. The weakness is classified as CWE‑416 and CWE‑825, indicating a classic use‑after‑free vulnerability that compromises memory safety and isolation guarantees, as well as potential covert data leak or uninitialized memory use.
Affected Systems
Affected deployments are Google Chrome browsers running versions earlier than 148.0.7778.216. Any user who diminishes the sandbox boundaries through this bug may be able to execute code outside the browser’s confined environment.
Risk and Exploitability
The issue carries Chromium’s “Critical” severity and is not yet catalogued in CISA’s KEV list, implying it is not actively used in publicized attacks to date. Although the EPSS score is not published, the nature of the vulnerability and its sandbox‑escape potential dictate a high risk, especially in environments where Chrome renders content from untrusted or adversarial sources. The most likely attack vector is a remote attacker delivering a malicious HTML page that is interpreted by the victim’s Chrome instance. The CVSS score of 9.6 further underscores the vulnerability’s critical nature.
OpenCVE Enrichment