Impact
A use‑after‑free flaw exists in the GetUserMedia API of Google Chrome. When a remote attacker compels a compromised renderer process to process a specially crafted HTML page, the flaw may enable the attacker to escape the renderer sandbox. The vulnerability is classified as CWE‑416. The likely attack vector involves a compromised renderer process as inferred from the description.
Affected Systems
Google Chrome versions prior to 150.0.7871.47 are vulnerable. Desktop installations that have not yet applied the update are potentially exposed. The advisory does not specify which operating systems or architectures are supported; desktop platforms should be considered at risk.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity impact if the flaw is triggered. An EPSS score of <1% suggests that the probability of exploitation in the wild is very low. The vulnerability is not listed in the CISA KEV catalog. Attackers must first compromise the renderer process, which may require exploitation of another vulnerability or some form of user interaction; this requirement is inferred from the description of the threat model. If the sandbox escape succeeds, the attacker could potentially execute code with elevated privileges, as inferred from the impact of a sandbox escape.
OpenCVE Enrichment
Debian DLA
Debian DSA