Impact
Use‑after‑free in ANGLE for Google Chrome on Windows before version 148.0.7778.216 can be triggered by a crafted HTML page when an attacker has already compromised the renderer process. The flaw allows the attacker to potentially escape the browser’s sandbox and execute code with higher privileges. This is a high‑severity vulnerability classified under CWE‑416 and CWE‑825.
Affected Systems
Google Chrome on Windows systems running a version older than 148.0.7778.216 are vulnerable. The issue affects the ANGLE graphics implementation used by Chromium.
Risk and Exploitability
The vulnerability is high in severity, as reflected by a CVSS score of 8.3. The EPSS score of <1% indicates a very low probability of exploitation, though confirmed exploitation is not yet documented. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation in the wild yet. The attack requires previous compromise of the renderer process, after which a specially crafted HTML document can trigger the use‑after‑free and lead to sandbox escape.
OpenCVE Enrichment