Impact
A use‑after‑free bug in the WebRTC component of Google Chrome allows a remote attacker to execute arbitrary code inside the browser’s sandbox by serving a specially crafted HTML page. The vulnerability is identified as CWE‑416 and CWE‑772 and is classified with a Chromium severity of Medium.
Affected Systems
Google Chrome desktop releases lower than version 149.0.7827.53 are affected. The stable‑channel update notes reference only the Desktop channel and do not list other platforms or channels as affected based on the available data.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity issue. The EPSS score of < 1% shows a low exploitation probability, suggesting that active attacks are unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote malicious web page, inferred from the requirement to deliver a specially crafted HTML page to the victim’s browser. The weaknesses are identified as CWE‑416 and CWE‑772.
OpenCVE Enrichment
Debian DSA