Impact
The vulnerability is a use‑after‑free flaw in Google Chrome's Accessibility code. An attacker who has already gained access to a compromised renderer process can craft a malicious HTML page that triggers the use‑after‑free. This flaw allows the attacker to escape the renderer sandbox, potentially executing arbitrary code with the privileges of the host operating system. Chromium has labeled the issue as High severity.
Affected Systems
Google Chrome for desktop, any stable channel build prior to version 148.0.7778.216, regardless of operating system.
Risk and Exploitability
The flaw is fatal when combined with a compromised renderer process; it can lead to complete Take‑Over of the host system. The CVSS score of 9.0 and the EPSS score of < 1% indicate a very high severity but a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The inherent severity and the potential for sandbox escape result in a high overall risk. The most probable attack path involves an attacker delivering a specially crafted HTML page to the targeted machine, which exploits the use‑after‑free and then escalates privileges from the renderer to the host.
OpenCVE Enrichment