CyberRota Analysis
AI-GeneratedA use-after-free vulnerability in the DataTransfer component of Google Chrome on Windows allows remote attackers to exploit a compromised renderer process, potentially leading to a sandbox escape through a specially crafted HTML page. This critical flaw (CVSS 9.6) poses significant risks to users, particularly those in environments where web applications are heavily utilized. Organizations using affected versions of Chrome should prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Related CVEs
Other vulnerabilities affecting the same vendor(s)