Impact
In Chrome on Windows versions prior to 149.0.7827.103, a use‑after‑free bug in the Media component of the browser allows an attacker to execute arbitrary code inside a sandboxed process when a specially crafted HTML page is rendered. This flaw is a classic memory‑management defect identified as CWE‑416 and can enable a remote attacker to gain control over the affected process, potentially leading to broader system compromise if sandbox escape succeeds. The consequence is loss of confidentiality, integrity, and availability of the user’s system if exploitation succeeds.
Affected Systems
All Windows installations of Google Chrome with a version earlier than 149.0.7827.103 are vulnerable. No additional sub‑version detail is provided, so the entire range of pre‑149.0.7827.103 requires remediation.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS data is unavailable, so the exact likelihood of exploitation cannot be quantified, but the vulnerability has been rated as high by Chromium’s internal assessment. It is not listed in the CISA KEV catalog. The likely attack vector is a maliciously crafted HTML page served over the web that a user may open in the browser; therefore vulnerability exploitation is user‑dependent, relying on a user to view the malicious content.
OpenCVE Enrichment