Impact
A use‑after‑free flaw in WebRTC allows a remote attacker to execute arbitrary code inside Chrome’s sandbox when a crafted HTML page is loaded. The vulnerability, identified as CWE‑416 and CWE‑825, can lead to manipulation of the browser process and compromise of the sandboxed execution context.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 on desktop platforms are affected. The flaw impacts all operating systems where the desktop browser runs, providing a universal attack surface for users of earlier releases.
Risk and Exploitability
The EPSS score for this issue is 0.00071, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is 8.8, indicating a high severity; the Chromium documentation rates the severity as Medium, reflecting a serious flaw. The likely attack vector involves a remote attacker controlling the content of a web page that a victim visits; the crafted HTML triggers the use‑after‑free while the browser is rendering the page.
OpenCVE Enrichment
Debian DSA