Impact
This vulnerability is a use-after-free condition in the Chromecast component of Google Chrome. When a remote attacker has managed to compromise the renderer process, they can supply a specially crafted HTML page that triggers the freed memory usage, enabling the attacker to execute arbitrary machine code outside of Chrome’s sandbox. The impact is full remote code execution on the host system, giving the attacker complete control over the affected machine. The weakness maps to CWE-416, a memory safety vulnerability that can lead to arbitrary code execution.
Affected Systems
Versions of Google Chrome released before the 152.0.7977.65 update are susceptible. The affected product is Google Chrome. The vulnerability is specifically tied to the Chromecast feature within the browser. Any environment running these earlier releases and enabling Chromecast could be impacted.
Risk and Exploitability
Based on the description, the likely attack vector is a crafted HTML page that reaches a renderer process that has already been compromised. The vulnerability is classified as high severity. The CVSS score of 9.6 underscores this high risk. The EPSS score is not available, and the exploit is not listed in CISA KEV, indicating no known widespread exploitation at this time. However, the attack requires the attacker to have already compromised the renderer process, which could be achieved via malicious web content or other vulnerabilities. Once renderer compromise is achieved, a crafted HTML page can trigger the use-after-free, allowing execution of arbitrary code outside the sandbox. The lack of a publicly tracked KEV instance does not diminish the risk, as the conditions for exploitation remain feasible in targeted or advanced threat scenarios.
OpenCVE Enrichment
Debian DLA
Debian DSA