Impact
Google Chrome for Windows contains a use‑after‑free bug in the Media component that can lead to a sandbox escape. This flaw, categorized as CWE‑416, allows a remote attacker who has already compromised the renderer process to execute code outside of the sandbox, potentially gaining full system privileges. The vulnerability could be triggered by a crafted HTML page, leading to significant confidentiality, integrity, and availability impact.
Affected Systems
Google Chrome installed on Windows machines running any version earlier than 151.0.7922.109 are vulnerable. Systems that have not yet applied the August 2026 stable channel update are at risk.
Risk and Exploitability
Chromium security severity is listed as High, and the EPSS score is not available at this time. The vulnerability is not part of the CISA KEV catalog. Exploitation likely requires remote delivery of malicious HTML to a compromised renderer. The attack vector is inferred from the description: a malicious website or attacker-controlled content served to the compromised renderer could trigger the use‑after‑free and escape the sandbox.
OpenCVE Enrichment