Impact
Use‑after‑free in the MediaRecording component in Google Chrome before 148.0.7778.96 can be triggered by a crafted HTML page. A remote attacker can persuade a user to perform specific UI gestures, causing the application to reference freed memory and execute arbitrary code.
Affected Systems
Google Chrome, versions earlier than 148.0.7778.96. The vulnerability affects users who load a malicious webpage and interact with the page’s UI.
Risk and Exploitability
The flaw is a high‑severity use‑after‑free (CWE‑416) and memory allocation flaw (CWE‑825) with a CVSS score of 7.5, enabling remote code execution. Exploitation requires the victim to visit a malicious site and perform specific UI gestures, which is infrequent but viable. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, yet the severity indicates significant risk when the conditions are met.
OpenCVE Enrichment
Debian DSA