Impact
A use‑after‑free vulnerability exists in the Cast component of Google Chrome releases prior to 150.0.7871.47. When triggered by a specially crafted web page, the flaw can allow an attacker who already has control of the renderer process to escape Chrome’s sandbox and execute code with elevated privileges. The core weakness is a classic memory corruption error identified as CWE‑416.
Affected Systems
All versions of Google Chrome older than 150.0.7871.47 are susceptible. The vulnerability resides in the Cast module, which is bundled with standard Chrome installations and can be accessed through normal browser usage.
Risk and Exploitability
The CVSS score of 9.6 indicates a high potential impact, yet the EPSS score of less than 1% signals a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Real‑world exploitation requires an attacker to first compromise the renderer process; without that foothold, the risk is limited to sessions where the renderer is already under attacker control. Consequently, the overall risk is limited but remains serious if the attack path is realized.
OpenCVE Enrichment
Debian DLA
Debian DSA