Impact
A use‑after‑free bug in the proxy component of Google Chrome enables an attacker to execute arbitrary code by supplying a specially crafted PAC script. This flaw is classified as CWE‑416 and CWE‑825 and is considered critical by Chromium’s own severity assessment.
Affected Systems
All installations of Google Chrome with a version earlier than 148.0.7778.216 that use the proxy functionality are vulnerable. The issue surfaces wherever a PAC script can be processed, which may occur on any platform that runs the affected browser.
Risk and Exploitability
The vulnerability can be triggered remotely by feeding the crafted PAC script through the network. With a CVSS score of 7.8, the flaw poses a high risk, and the EPSS score is < 1%. The issue is not listed in CISA’s KEV catalog, but the nature of the flaw would allow an attacker full code execution on the affected machine. No public exploit has been reported yet, but the EPSS score of < 1% does not mitigate the potential risk.
OpenCVE Enrichment