Impact
This vulnerability is a use‑after‑free in Chrome's WebMIDI implementation. When an attacker can compromise the renderer process, such as by loading a specially crafted web page, the flaw can trigger a memory corruption that allows the attacker to escape the browser sandbox and execute arbitrary code with elevated privileges. The flaw is classified as CWE‑416 and is considered a high‑severity issue by Chromium’s security team.
Affected Systems
Google Chrome desktop browsers with versions earlier than 147.0.7727.138 are affected. The issue is limited to the desktop release and does not exist in prior patched revisions.
Risk and Exploitability
The CVSS score of 8.3 indicates a high impact on confidentiality and integrity. The EPSS score is < 1 %, suggesting a very low but non‑zero likelihood of exploitation, and it is not listed in CISA’s KEV catalog. Exploitation requires a compromised renderer process, typically achieved through malicious HTML content or a crafted web page, making the attack technically demanding but feasible for an adversary who can deliver such content to the vulnerable browser.
OpenCVE Enrichment
Debian DSA