Impact
Use after free in the Streaming component of Google Chrome allows a remote attacker who tricks a user into opening a crafted HTML page to potentially execute arbitrary code inside the sandbox, enabling compromise of the user’s browser session.
Affected Systems
The affected product is Google Chrome; vulnerabilities exist in all pre‑155.0.8059.39 builds on desktop platforms.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting a moderate likelihood of exploitation in the wild. Attackers would need to deliver a malicious HTML payload, most likely via social engineering, to trigger the use after free condition and achieve remote code execution within the browser sandbox.
OpenCVE Enrichment