Impact
This flaw is a use‑after‑free bug in Chrome’s WebRTC component that allows a remote attacker to execute arbitrary code inside the browser’s sandbox by loading a specially crafted HTML page. The vulnerability can lead to either data disclosure or escalation within the sandbox, and because the exploit occurs within a sandboxed environment, the potential for a full system compromise depends on other weaknesses that might be leveraged afterwards.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected. Only the desktop Stable channel is mentioned in the publicly released update notes.
Risk and Exploitability
The vulnerability has a Chromium severity of Medium and is not yet listed in the CISA KEV catalog. Exploitation requires the victim to visit a malicious web page, which is a remote attack vector. The EPSS score is not available, so the likelihood of active exploitation cannot be quantified, but the potential impact remains high due to the remote code execution capability within the sandbox.
OpenCVE Enrichment