Impact
A use‑after‑free flaw in the media subsystem of Google Chrome versions prior to 147.0.7727.55 allows a remote attacker to trigger arbitrary code execution within the sandboxed renderer process by delivering a crafted HTML page. The vulnerability is categorized as a High severity vulnerability in the Chromium security model.
Affected Systems
The affected product is Google Chrome versions older than 147.0.7727.55. The flaw impacts all major operating systems covered by the designated CPEs, namely macOS, Windows, and Linux distributions. Users of these browsers who have not yet upgraded are susceptible.
Risk and Exploitability
The reported CVSS score of 8.8 indicates a high severity risk. The EPSS score of less than 1% suggests a low probability that exploitation attempts have been observed in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack likely requires that the victim opens a malicious HTML page, as implied by the description, but the explicit attack vector is not detailed in the CVE information and is therefore inferred.
OpenCVE Enrichment
Debian DSA