Impact
A use‑after‑free vulnerability exists in the Chromecast implementation of Google Chrome. The flaw can be triggered when a renderer process has already freed a memory region but still attempts to access it. An attacker who can compromise the renderer can use a crafted HTML page to execute arbitrary code outside of the browser sandbox, allowing full control over the system. The volatility of this bug is reflected in the Chromium reporting it as a Critical severity issue.
Affected Systems
The vulnerability affects the stable channel of Google Chrome on desktop platforms running versions earlier than 152.0.7977.65. Any system that continues to use an older Chrome release is potentially exposed.
Risk and Exploitability
The CVSS base score of 8.3 indicates a High level of severity, and the exploit requires compromise of the renderer process, which is a higher‑privilege state. While the EPSS score of <1% indicates a very low likelihood of exploitation, no known exploits are listed in the CISA KEV catalog, implying that active exploitation is not yet documented. Nevertheless, the combination of high impact and the ability to escape the sandbox represents a significant risk for any user who visits malicious web content or sites capable of impacting the renderer.
OpenCVE Enrichment
Debian DLA
Debian DSA