Impact
A use‑after‑free flaw in Chrome’s Media component allows a remote attacker who has already compromised the renderer process to execute arbitrary code inside the browser’s sandbox. The vulnerability is triggered by a specially crafted HTML page, enabling the attacker to run code with the sandboxed renderer’s privileges, which can lead to privilege escalation and total compromise of the host if the sandbox is bypassed.
Affected Systems
Google Chrome browsers running any desktop platform version prior to 149.0.7827.155 are affected. The flaw exists in the stable channel releases and applies to all operating systems where Chrome is installed.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of widespread exploitation at present. However, the CVSS severity is High and the attack requires delivery of malicious HTML through the renderer process, suggesting that an attacker could employ phishing or drive‑by‑download techniques. Successful exploitation would grant code execution within the sandbox, potentially enabling more invasive attacks if the sandbox is leveraged.
OpenCVE Enrichment