Impact
A use‑after‑free vulnerability exists in the Views component of Google Chrome before version 148.0.7778.216. If an attacker has already taken control of the renderer process, the flaw can enable the attacker to escape the sandbox and potentially execute arbitrary code outside the browser’s restricted environment. The weakness corresponds to CWE-416 and CWE-825, and Chromium security assigns it a high severity rating.
Affected Systems
All versions of Google Chrome older than 148.0.7778.216, regardless of operating system, are vulnerable because the issue resides in a core component used by Windows, macOS, and Linux distributions.
Risk and Exploitability
Based on the description, the likely attack vector requires an attacker to first gain control of the renderer process, typically by delivering a crafted PDF file that Chrome parses. Once the renderer is compromised, the use‑after‑free can be triggered to escape the sandbox. The CVSS score of 8.3 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but should be mitigated promptly.
OpenCVE Enrichment