PT-2026-8021 · Google+1 · Google Chrome+1
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 145.0.7632.75
Description
A high-severity use-after-free vulnerability exists in the CSS component of the Blink renderer, specifically within the
CSSFontFeatureValuesMap structure. The issue is caused by incorrect iterator invalidation when processing the @font-feature-values property, leading to memory corruption in the browser's render process. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page containing malicious CSS, which allows for arbitrary code execution inside the browser sandbox. This issue has been confirmed as exploited in the wild.Recommendations
Update Google Chrome to version 145.0.7632.75 or 145.0.7632.76 for Windows and macOS.
Update Google Chrome to version 144.0.7559.75 for Linux.
Exploit
Fix
RCE
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Chrome
Red Os