Impact
A use‑after‑free flaw was discovered in Chrome's XML parsing code, allowing a remote attacker to execute arbitrary code inside the browser's sandbox. Based on the description, it is inferred that an attacker could attempt to escape the sandbox to gain higher privileges or modify browser state, though this is not explicitly confirmed.
Affected Systems
Versions of Google Chrome earlier than 148.0.7778.216 on any operating system are affected. The issue was fixed in Chrome update 148.0.7778.216 and later.
Risk and Exploitability
Chromium classifies the exploit as high severity, with a CVSS score of 8.8, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious webpage that the user visits or opens, which can be delivered via phishing or compromised site. Based on the description, it is inferred that an attacker who successfully exploits the use‑after‑free can run code with the privileges of the Chrome process, potentially bypassing sandbox protections.
OpenCVE Enrichment