Impact
A use‑after‑free flaw in Chromecast logic inside Google Chrome allows an attacker who has already compromised the renderer process to run arbitrary code outside the renderer sandbox. Because the flaw occurs in the rendering engine, it can be triggered by a crafted HTML document, giving the attacker full control of the host system. The vulnerability is classified as critical by Chromium's security team.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65. The affected component is the Chromecast module in the renderer process.
Risk and Exploitability
The CVSS base score is 8.3, but Chromium deems the issue critical. Exploitation requires that the attacker already has control over the renderer process, which typically means the attacker has bypassed the browser sandbox or performed a local privilege escalation. The EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. If the renderer process can be compromised, the attacker can execute code with the privileges of the Chrome user or even system privileges if further exploit steps are available.
OpenCVE Enrichment
Debian DLA
Debian DSA