Impact
This vulnerability is a use‑after‑free (CWE‑416) and also involves an improper restriction of operation (CWE‑825) in the WebRTC component of Google Chrome for Linux. A crafted HTML page can trigger the flaw, allowing a remote attacker to execute arbitrary native code. The flaw is a classic memory unsafety that permits execution of code not intended by the normal program flow, potentially compromising the system on which the vulnerability exists.
Affected Systems
All users running Google Chrome on Linux with a version earlier than 149.0.7827.53 are vulnerable, including the stable channel on desktop Linux platforms.
Risk and Exploitability
The CVSS score for this vulnerability is 8.8, indicating a high severity. The EPSS score is 0.00071, which is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. The attack is likely to require a victim to open a maliciously crafted web page or visit a site that serves a crafted WebRTC‑enabled document. If exploited successfully, it could enable the attacker to run arbitrary native code on the victim's machine.
OpenCVE Enrichment
Debian DSA