Impact
The vulnerability is a use‑after‑free bug in the Network component of Google Chrome that allows a remote attacker to execute arbitrary code inside a sandboxed process. By crafting a malicious HTML page, an attacker can force the browser to free memory and then read from that freed location, triggering unintended control flow. This weakness corresponds to CWE‑416 and to CWE‑825.
Affected Systems
All desktop installations of Google Chrome that use a build prior to version 148.0.7778.216. The flaw applies to any channel (stable, beta, dev) where the affected build is in use.
Risk and Exploitability
Chromium classifies the issue as high severity, with a CVSS score of 8.8, and it is not listed in the CISA KEV catalog. EPSS data is unavailable, so a quantifiable exploitation probability cannot be stated. The attack requires the victim to load a specifically crafted HTML page—something that can be delivered via a compromised or malicious website. Until the browser is updated, systems remain vulnerable to remote code execution confined to the sandboxed environment.
OpenCVE Enrichment