Impact
This vulnerability is a use‑after‑free flaw in the Chromecast component of Google Chrome versions earlier than 149.0.7827.53. An attacker with control of a compromised renderer process can craft a malicious HTML page that triggers the freed memory usage, enabling the attacker to escape the browser sandbox and execute code with the privileges of the host process. The flaw is defined as CWE‑416, a fundamental memory management error that directly compromises integrity and confidentiality, and CWE‑825.
Affected Systems
Google Chrome, the desktop stable channel, any installation running a version prior to 149.0.7827.53. The issue is limited to the Chromecast feature within the browser.
Risk and Exploitability
Chromium rates the issue as Critical, with a CVSS score of 8.3. The EPSS score is reported to be very low, less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploits have been observed in the wild. However, the need to compromise the renderer process can be achieved by serving a malicious web page, so the likelihood of exploitation is non‑negligible for active users of the affected Chrome versions. The only effective defense is to remove the flaw via an official update.
OpenCVE Enrichment
Debian DSA