Impact
A use‑after‑free flaw in Chrome’s WebCodecs implementation allows a malicious website to trigger arbitrary code execution inside the browser sandbox. The vulnerability is identified as a use‑after‑free (CWE‑416) and is described as enabling a remote attacker to run attacker‑controlled code within the sandboxed process.
Affected Systems
The flaw is present in Google Chrome versions prior to 146.0.7680.178 on all desktop platforms, including Windows, macOS, and Linux, affecting users who have not applied the latest update.
Risk and Exploitability
The CVSS score of 8.8 reflects the serious impact of an exploitation that would result in arbitrary code execution in the sandbox. The EPSS score of less than 1% indicates an overall low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers would likely deliver a crafted HTML page containing malicious WebCodecs usage to trigger the use‑after‑free and execute code within the browser process.
OpenCVE Enrichment
Debian DSA