Impact
A use‑after‑free flaw in the handling of Chrome extensions allows a remote attacker who has already compromised the browser’s renderer process to potentially escape the sandbox. This vulnerability can enable the attacker to execute arbitrary code at the system level, compromising confidentiality, integrity, and availability of the host machine. The flaw corresponds to CWE‑416 and CWE‑825.
Affected Systems
Google Chrome versions prior to 148.0.7778.216 are affected. All installations that allow extensions to run in the Chrome renderer are susceptible unless they are updated to the specified or later patch version.
Risk and Exploitability
The flaw is classified as Critical by Chromium, with a CVSS score of 9.0, indicating high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker already has control over the renderer process, typically through a malicious or compromised Chrome extension. When that condition is met, the flaw can be leveraged to escape the browser sandbox and gain system access.
OpenCVE Enrichment