Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review/
https://thehackernews.com/2025/12/intellexa-leaks-reveal-zero-days-and.html
https://thehackernews.com/2024/08/russian-hackers-exploit-safari-and.html
https://www.tenable.com/cyber-exposure/2021-threat-landscape-retrospective