Impact
A use‑after‑free flaw in the WebMIDI implementation of Google Chrome on Windows allows a remote attacker who has already compromised the renderer process to escape the browser sandbox and potentially execute arbitrary code on the host system. The vulnerability is a classic memory corruption error (CWE‑416) and is assessed as Critical by Chromium security reviewers.
Affected Systems
Google Chrome running on Windows with versions prior to 149.0.7827.115 are vulnerable. All affected installations should be considered at risk and treated as potentially compromised if an attacker can serve a crafted HTML page with WebMIDI requests.
Risk and Exploitability
EPSS information is not available and the vulnerability is not listed in CISA’s KEV catalog, but the stated Chromium severity of Critical indicates a high likelihood of exploitation by a skilled adversary. Exploitation requires control over a renderer process via a malicious HTML page served to the user; once the renderer is compromised, the attacker can perform a sandbox escape thanks to the use‑after‑free. The lack of a public EPSS score does not diminish the urgency, as the vulnerability remains a high-value target for attackers seeking local privilege escalation.
OpenCVE Enrichment