Impact
This vulnerability is a use‑after‑free flaw in the Chromecast component of Google Chrome versions earlier than 149.0.7827.53. An attacker with control of a compromised renderer process can craft a malicious HTML page that triggers the freed memory usage, enabling the attacker to escape the browser sandbox and execute code with the privileges of the host process. The flaw is defined as CWE‑416, a fundamental memory management error that directly compromises integrity and confidentiality.
Affected Systems
Google Chrome, the desktop stable channel, any installation running a version prior to 149.0.7827.53. The issue is limited to the Chromecast feature within the browser.
Risk and Exploitability
Chromium rates the issue as Critical, with a CVSS score of 8.3. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog, implying that no known exploits have been observed in the wild yet. However, the need to compromise the renderer process can be achieved by serving a malicious web page, so the likelihood of exploitation is non‑negligible for active users of the affected Chrome versions. The only effective defense is to remove the flaw via an official update.
OpenCVE Enrichment