Impact
A use‑after‑free flaw was discovered in the Aura UI framework of Google Chrome, affecting releases prior to 148.0.7778.216. This vulnerability is a CWE‑416 and CWE‑825 condition that can lead to remote code execution when a crafted HTML page forces a user to perform specific UI gestures. The flaw enables an attacker to execute arbitrary code within the browser context, which in turn could allow further compromise of the host system.
Affected Systems
Google Chrome is affected when the browser version is below 148.0.7778.216. No other vendors or product variants are listed as impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity per the Chromium security team. The EPSS score is currently unavailable, and the issue is not cataloged in the CISA KEV list. Exploitation requires the attacker to lure a user to engage with a specially crafted web page, implying a social‑engineering component. The lack of a publicly available proof‑of‑concept suggests that while the risk is high, the likelihood of widespread exploitation remains uncertain, though it could be used in targeted attacks.
OpenCVE Enrichment