Impact
Based on the description, it is inferred that a use‑after‑free bug in the Cast component of Google Chrome allows an attacker on the same local network to send crafted Cast traffic that causes heap corruption. This flaw, identified as CWE‑416, could lead to arbitrary code execution or a denial‑of‑service condition. Chromium classifies this as high severity, indicating significant risk if exploited.
Affected Systems
Google Chrome browsers on the stable channel built before version 147.0.7727.138 are affected. The flaw exists in the desktop build of Chromium that ships with Chrome on Windows, macOS, and Linux operating systems.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is less than 1%, suggesting low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves a local network attacker sending malicious Cast traffic. The description does not confirm the existence of publicly documented exploits, but the potential for arbitrary code execution means the risk remains significant.
OpenCVE Enrichment
Debian DSA