Impact
The vulnerability is a use‑after‑free in the Chromoting component of Google Chrome. When the browser processes malicious network traffic, it may access memory that has already been freed, which can allow an attacker to execute arbitrary code. The CVE indicates a high severity but does not specify the privilege level of the code execution.
Affected Systems
Google Chrome versions older than 147.0.7727.138 are affected; any platform running these versions with the Chromoting feature enabled is potentially vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.1, indicating a very high severity rating. The EPSS score is less than 1%, indicating a very low probability of exploitation, and it is not listed in the CISA KEV catalog. Nevertheless, because arbitrary code execution can be achieved via network traffic, the potential for exploitation remains significant. The issue is classified as CWE‑416 and CWE‑825 and warrants prompt remediation.
OpenCVE Enrichment
Debian DSA