Impact
The vulnerability is a use‑after‑free bug in the Chromecast component of Google Chrome. It enables a remote attacker who can serve a crafted HTML page to execute arbitrary code inside the browser sandbox. This flaw is a classic memory‑safety issue (CWE‑416) that would allow an attacker to run code with the same privileges as the browser process.
Affected Systems
All installations of Google Chrome prior to build 152.0.7977.65 are affected. No other products or versions are listed as impacted.
Risk and Exploitability
No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but the Chromium security team rated it High, with a CVSS score of 8.8. The attack requires an attacker to host a malicious page in a way that the user visits or a compromise that injects code into Chrome, then the crafted HTML triggers the use‑after‑free. Successful exploitation would give the attacker code execution with sandbox privileges, which could lead to privilege escalation or full system compromise if additional post‑exploitation techniques are applied.
OpenCVE Enrichment
Debian DLA
Debian DSA