Impact
A use‑after‑free flaw in the ANGLE graphics library within Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox by delivering a specially crafted HTML page. This vulnerability permits the attacker to run code with any privileges granted to the sandboxed rendering process, potentially compromising the user’s data and system integrity. The weakness is identified as CWE-416 and CWE-825.
Affected Systems
Google Chrome browsing clients running any version earlier than 148.0.7778.216 are affected. No other vendor products are listed as impacted.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high severity in the Chromium security model. The EPSS score is <1% and the vulnerability is not currently listed in the CISA KEV catalog, but the fact that remote code execution can be achieved via a crafted web page indicates a high potential impact. Based on the description, it is inferred that the attack vector is a malicious or compromised web page that serves the crafted content, allowing an attacker to trigger the use‑after‑free from any user‑visible page they control.
OpenCVE Enrichment