Impact
This vulnerability is a use‑after‑free flaw in the Media stack of Google Chrome. When a crafted video file is processed by Chrome versions earlier than 149.0.7827.53, the freed memory is accessed again, allowing an attacker to execute arbitrary code within the browser’s sandbox. Because the code runs inside the sandbox process, it can potentially escape the sandbox or be exploited to compromise the host system if the sandbox is already bypassed. The weakness is identified as both CWE‑416 (Use After Free) and CWE‑825 (Use After Free in a Heap Allocation Context).
Affected Systems
Google Chrome browsers running any pre‑149.0.7827.53 build.
Risk and Exploitability
The CVSS score is 8.8; the EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, but the Chromium project rates it as Medium severity. Based on the description, it is inferred that the flaw can be exploited remotely via a crafted video file delivered over the network. An attacker is likely to entice a user to open or double‑click the malicious file or to embed it in a remote webpage that the user visits. Because it triggers within a sandboxed renderer, escape to the host depends on other sandbox weaknesses, but originating code execution is possible. The EPSS score indicates a low likelihood of exploitation, yet the high impact warrants immediate action.
OpenCVE Enrichment
Debian DSA