Impact
A use‑after‑free flaw in the Media component of Google Chrome allows a remote attacker to trigger arbitrary code execution inside the browser’s sandbox by loading a specifically crafted HTML page. The vulnerability originates from unsafe handling of freed memory in media processing, enabling the attacker to inject executable code that runs with the privileges of the sandboxed process.
Affected Systems
Google Chrome versions prior to 155.0.8059.39 are affected on all supported platforms. The flaw was present in the stable channel at the time of the advisory and affects any instance of the browser that processes media content from web pages.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, through a malicious web page that a user visits. Successful exploitation would allow code execution inside the browser sandbox, which could be used for privilege escalation or lateral movement if exploited in conjunction with other weaknesses.
OpenCVE Enrichment