Impact
A use‑after‑free flaw exists in the Cast component of Google Chrome, allowing a remote attacker to execute arbitrary code inside the browser sandbox by serving a crafted HTML page. The flaw arises from improper handling of freed memory during cast requests, which can be triggered by malicious JavaScript. Based on the description, it is inferred that attackers can exploit this vulnerability without requiring further user interaction beyond opening the page.
Affected Systems
Google Chrome versions prior to 150.0.7871.128, specifically the desktop Chromium‑based browser’s Cast feature, are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of < 1% reflects a low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread attacks. Attackers can exploit the flaw by delivering a malicious web page that engages the Cast API, leading to sandboxed code execution. Based on the description, it is inferred that no additional user interaction beyond opening the page is required.
OpenCVE Enrichment
Debian DLA
Debian DSA