Impact
The vulnerability is a use‑after‑free that occurs when Chrome's Media components on Windows release memory that can later be accessed again. A remote attacker delivering a crafted HTML page can trigger the memory reuse, which may allow the attacker to escape the browser sandbox and execute code with higher privileges. This flaw is identified as CWE‑416 (Use After Free) and CWE‑825 (Improper Management of Uninitialized Resource) and is considered high severity by Chromium.
Affected Systems
Google Chrome browsers running on Windows with versions earlier than 151.0.7922.109 are affected. All supported Windows platforms that ship these Chrome builds are at risk. The issue does not affect Chrome installations on other operating systems.
Risk and Exploitability
The CVSS score of 9.6 indicates a severe risk, while the EPSS score of <1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits. The flaw involves both a use‑after‑free (CWE‑416) and improper resource cleanup (CWE‑825), providing multiple potential exploitation paths. The likelihood of exploitation hinges on the attacker’s ability to serve a malicious HTML page to a user. If the sandbox is enabled, the attacker’s capabilities are limited, but a potential break out into the host system remains possible.
OpenCVE Enrichment
Debian DLA
Debian DSA