Impact
The vulnerability is a use‑after‑free in the Media component of Google Chrome that permits a remote attacker to execute arbitrary code inside the browser’s sandbox by presenting a crafted HTML page. The flaw arises when the browser deallocates memory and subsequently accesses it, allowing the attacker to inject malicious code that can run with the browser process’s privileges.
Affected Systems
Google Chrome desktop browsers before version 147.0.7727.138 are affected. This issue resides in the Media handling code that processes HTML content loaded into the browser.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no currently known public exploitation. The official Chromium severity rating is Medium. The flaw requires a maliciously crafted HTML page served to or opened by the victim. The likely attack vector is a malicious website or drive‑by download; it is inferred that the attacker would need to convince the user to load the page. No public exploits have been reported. Once exploited, the attacker can run arbitrary code inside the sandbox, and it is inferred that additional privilege escalation might be possible if the sandbox can be bypassed, although this is not explicitly documented.
OpenCVE Enrichment