Impact
The flaw is a use‑after‑free in Chrome’s Cast integration that can corrupt heap allocations when malicious network traffic is received. This constitutes CWE‑416 and, if successfully triggered, can potentially allow an attacker to execute arbitrary code in the browser process, leading to compromise of the client machine.
Affected Systems
Google Chrome on all platforms. Releases earlier than 149.0.7827.53 are affected. Chrome 149.0.7827.53 and later contain the fix referenced in the update blog.
Risk and Exploitability
With a CVSS score of 8.8, Chromium labels the issue as Critical. No EPSS score is available. The vulnerability is not listed in CISA’s KEV catalog. The attack vector requires the attacker to be on the same local network segment and to send crafted traffic that the Cast code will process; the attacker does not need to remotely access the victim’s machine over the public Internet. Successful exploitation would give code execution in the context of the Chrome user.
OpenCVE Enrichment