Impact
The vulnerability is a use‑after‑free flaw in the Chromecast component of Google Chrome. Prior to version 150.0.7871.47 the flaw allows a remote attacker who has already compromised the renderer process via a crafted HTML page, which can lead to arbitrary code execution. The weakness is classified as CWE‑416.
Affected Systems
Google Chrome users running any version older than 150.0.7871.47 on any platform are affected. The defect resides in the Chromecast subsystem that operates within the renderer process of Chrome.
Risk and Exploitability
According to the CVE description, the flaw is a use‑after‑free in the Chromecast subsystem of Google Chrome. Exploitation requires an attacker to inject a specially crafted HTML page while the renderer process has already been compromised, allowing the malicious code to trigger the use‑after‑free and potentially escape the renderer sandbox. The CVSS score of 8.3 denotes high severity, while an EPSS score of <1% suggests low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no widespread exploitation has been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA