Impact
This vulnerability is a use‑after‑free flaw in the Video component of Google Chrome on Windows. When a renderer process has already been compromised by a remote attacker, a specially crafted HTML page can cause Chrome to perform memory accesses outside the intended bounds. The out‑of‑bounds access leads to memory corruption, which can compromise the stability of the renderer and potentially enable further exploitation. The weakness is categorized as CWE‑416 and CWE‑825.
Affected Systems
Google Chrome browser installations on Windows that are running a version prior to 147.0.7727.101, which contain the vulnerable Video component used during web page rendering.
Risk and Exploitability
The flaw has a CVSS score of 8.8, denoting high severity. An EPSS score has not been published, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker already controls the renderer process; thus, it is not a first‑stage remote exploit. Although the attack conditions are restrictive and no public exploit has been documented, the potential for memory corruption and the high CVSS warrant remediation and vigilant monitoring.
OpenCVE Enrichment
Debian DSA