Impact
The vulnerability is a use‑after‑free that occurs when Chrome's Media components on Windows release memory that can later be accessed again. A remote attacker delivering a crafted HTML page can trigger the memory reuse, which may allow the attacker to escape the browser sandbox and execute code with higher privileges. This flaw is identified as CWE‑416 and is considered high severity by Chromium.
Affected Systems
Google Chrome browsers running on Windows with versions earlier than 151.0.7922.109 are affected. All supported Windows platforms that ship these Chrome builds are at risk. The issue does not affect Chrome installations on other operating systems.
Risk and Exploitability
The CVSS assessment for this flaw is high, but no EPSS score is available, and it is not listed in the CISA KEV catalog, indicating no publicly known exploits so far. The likelihood of exploitation depends on the attacker’s ability to serve a malicious HTML page to a user. If the sandbox is enabled, the attacker’s capabilities are limited, but the possibility of breaking out into the host system still exists. The missing EPSS data means the exploitation probability is uncertain, and users should consider the high severity as a signal to take remediation seriously.
OpenCVE Enrichment