Impact
A use‑after‑free issue in Google Chrome’s PDF parser before build 148.0.7778.216 (CWE‑416, CWE‑825) allows a remote attacker to run arbitrary code within the browser’s sandbox through a crafted PDF file. The flaw can compromise the integrity and availability of the Chrome process, and while the description confirms sandbox execution, it does not assert any additional privilege escalation or system‑level impact.
Affected Systems
All desktop installations of Google Chrome older than version 148.0.7778.216 on Windows, macOS, and Linux are affected. No further sub‑version detail is provided, so applying any later stable release that contains the patch is the recommended approach.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score, listed as less than 1%, suggests a very low probability of exploitation at the time of this analysis, and the vulnerability is not identified in CISA KEV. The attack vector is remote, as the exploit requires the delivery of a malicious PDF file to the user. Based on the description, it is inferred that a user must open or render the PDF in Chrome for the flaw to be triggered; no additional authentication or privilege escalation is required.
OpenCVE Enrichment