Impact
Google Chrome versions prior to 152.0.7977.65 contain a use‑after‑free flaw in the WebRTC implementation that allows a malicious web page to trigger arbitrary code execution within the browser sandbox. This flaw is classified as a high‑severity vulnerability and can be leveraged by an attacker to compromise the host system if the victim visits a crafted web page.
Affected Systems
The issue affects Google Chrome across all platforms that include the WebRTC engine. Any instance of Chrome running a version earlier than 152.0.7977.65 is susceptible; newer releases patch the vulnerability.
Risk and Exploitability
The attack vector requires a victim to open a malicious web page, thus exploitation is likely in scenarios where users browse untrusted content. Although no EPSS or KEV data is currently available, the absence of such metrics does not diminish the high impact inherent to this flaw. The CVSS score is 8.8, indicating a high severity, and organizations should treat this as a top‑priority risk.
OpenCVE Enrichment
Debian DLA
Debian DSA