Impact
Google Chrome for Windows contains a use‑after‑free bug in the Media component that can lead to a sandbox escape. This flaw, categorized as CWE‑416 and CWE‑825, allows a remote attacker who has already compromised the renderer process to execute code outside of the sandbox, potentially gaining full system privileges. The vulnerability could be triggered by a crafted HTML page, leading to significant confidentiality, integrity, and availability impact.
Affected Systems
Google Chrome on Windows is potentially vulnerable, but the CVE data does not provide a specific affected version range. The August 2026 stable channel update is known to contain the fix, so systems that have not yet applied this update remain at risk.
Risk and Exploitability
Chromium security severity is listed as High, and the CVSS score is 8.3. The EPSS score is below 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not part of the CISA KEV catalog. Exploitation likely requires remote delivery of malicious HTML to a compromised renderer. The attack vector is inferred from the description: a malicious website or attacker‑controlled content served to the compromised renderer could trigger the use‑after‑free and escape the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA