Impact
The vulnerability is a use–after–free in the Media module of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox via a specially crafted HTML page. This results in remote code execution that may compromise confidentiality, integrity, and availability of the victim’s system. The weakness is defined by CWE-416 and CWE-825, indicating improper memory management and exceeding buffer bounds.
Affected Systems
Google Chrome browsers prior to version 147.0.7727.55 are vulnerable. Users on any operating system using these versions must update to the fixed release.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, classifying it as high. Its EPSS score is less than 1 %, suggesting low exploitation probability, and it has not been listed in the CISA KEV catalog. Based on the description, the attack vector is remote through a crafted web page, requiring the user to load the page in Chrome.
OpenCVE Enrichment
Debian DSA