Impact
The vulnerability is a use‑after‑free condition in the WebRTC component of Google Chrome that can lead to heap corruption when a browser processes a specially constructed HTML page. This flaw maps to CWE‑416 and could enable an attacker to tamper with memory, potentially allowing remote code execution. The assessment notes that the impact is considered high, with a CVSS score of 8.8.
Affected Systems
Chrome users running any build prior to version 146.0.7680.153 on macOS, Linux, or Windows are affected. The issue is tied to the Chrome binary distributed by Google, regardless of the operating system. No other browsers or products are listed as impacted.
Risk and Exploitability
Because the flaw requires delivering a crafted HTML page, the attack vector is remote via the user’s browser. The EPSS score indicates a low probability of exploitation in the wild, and the vulnerability is not in the CISA Known Exploited Vulnerabilities list. However, the high CVSS severity means that once compromised, an attacker could gain code execution within the browser process, posing a significant threat to confidentiality and integrity if the user visits malicious sites.
OpenCVE Enrichment
Debian DSA