Impact
A use‑after‑free bug in the Chromium UI allows a remote attacker to run arbitrary code on a Windows system by loading a specially crafted HTML page. The flaw is classified as CWE‑416 and CWE‑825 and carries a high severity rating in Chromium’s security scale.
Affected Systems
Google Chrome on Windows systems, any version prior to 148.0.7778.216, is affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8 and an EPSS score of < 1%, indicating a very low but non‑zero exploitation probability. It is not listed in the CISA KEV catalog. An attacker can exploit this flaw by serving a malicious HTML page to users on affected Chrome installations, potentially achieving full code execution with the privileges of the browsing process.
OpenCVE Enrichment