Use after free in Aura in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 148.0.7778.96 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| chrome | cert_advisory | 90% | |
| microsoft | windows | cve_cpe | 95% |
Updated vendor to Microsoft and product to Edge, and marked exploit as available.
Updated severity to CRITICAL, added new affected version 147.0.7727.138, and marked the vulnerability as actively exploited.
Initial creation