Impact
This vulnerability is a use‑after‑free flaw (CWE-416) in the WebRTC implementation of Google Chrome. A remote attacker can exploit it by delivering a specially crafted HTML page that causes the browser to free memory that is still being accessed, allowing execution of arbitrary code. The flaw can be leveraged from a web page, meaning an attacker does not need privileged access, and can run code within the browser's sandboxed environment, potentially bypassing additional constraints.
Affected Systems
All users running unsafeguarded versions of Google Chrome prior to 149.0.7827.53 are affected. The problem exists only in the WebRTC stack and is specific to the Chrome browser.
Risk and Exploitability
Because the flaw resides in a widely deployed browser and can be triggered by a malicious website, the risk to users is significant. The flaw permits remote code execution—a highly severe impact—and it is a CWE-416 Use‑After‑Free issue. No publicly available EPSS score is reported and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to host or serve a malicious page and convince a user to visit it, but the path is straightforward and does not require special system configuration or peripheral devices. The CVSS score is 8.8, indicating a high severity vulnerability.
OpenCVE Enrichment