Impact
A use‑after‑free bug exists in the media codec component of Google Chrome before version 147.0.7727.138. When a crafted HTML page is rendered, the bug causes a memory region that has already been freed to be accessed again, enabling an attacker to run code inside the browser’s sandboxed renderer process. The vulnerability allows the execution of arbitrary code, presenting a high‑severity risk for affected browsers.
Affected Systems
The flaw affects all Google Chrome installations on supported platforms—desktop, mobile, and web—where the version is older than 147.0.7727.138. Any stable channel build of Chrome that predates this release is vulnerable.
Risk and Exploitability
The issue is rated as high severity by Chromium security. An attacker who can supply a tailored web page can trigger the use‑after‑free from any remote location without the need for local credentials. No EPSS score is available, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attacker can execute arbitrary sandboxed code, which could be used for further attacks from within the confined renderer process.
OpenCVE Enrichment