Impact
The vulnerability is a use‑after‑free flaw in the Chromecast component of Google Chrome versions prior to 150.0.7871.47. The flaw allows a remote process via a crafted HTML page to trigger the use‑after‑free and potentially gain arbitrary code execution, classified as CWE‑416.
Affected Systems
Google Chrome users running any version older than 150.0.7871.47 on any platform are in the Chromecast subsystem that operates within the renderer process of Chrome.
Risk and Exploitability
According to the flaw is a use‑after‑free in the Chromecast subsystem of Google Chrome. Exploitation requires a specially crafted HTML page while the renderer process has already been compromised, allowing the malicious code to trigger the use‑after‑free and potentially escape the renderer sandbox. The CVSS score of 8.3 denotes high severity, while an EPSS score of <1% suggests low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no widespread exploitation has been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA