Impact
The vulnerability is a use‑after‑free flaw in the WebRTC component of Google Chrome that allows an attacker to execute arbitrary code within the sandbox when crafted network traffic is processed. This flaw can lead to full compromise of the host system if the attacker can escape the sandbox. The weakness is identified as CWE‑416, a classic use‑after‑free defect.
Affected Systems
All users running versions of Google Chrome earlier than 152.0.7977.65 are affected regardless of platform, because the vulnerability resides in the core WebRTC code shipped with the browser. Any machine that receives specially crafted WebRTC packets from the network is at risk.
Risk and Exploitability
The CVE has a CVSS score of 8.1, which is regarded as High. It currently has no publicly available exploit code and is not listed in CISA’s KEV catalog. The exploit path requires remote access to the target’s network stack, so the attack vector is inferred to be network. Although the EPSS score is not available, the lack of an active exploitation campaign does not diminish the potential impact of a successful attack, especially given the remote code execution nature of the flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA