Impact
Use‑after‑free in WebAudio allows a remote attacker to craft a malicious HTML page that triggers a memory corruption bug, enabling execution of arbitrary code inside Chrome’s sandbox. The flaw is a classic use‑after‑free (CWE‑416) that can also expose sensitive data or resources (CWE‑825), giving an attacker full control over the victim’s browser process.
Affected Systems
The affected product is Google Chrome on all platforms for versions prior to 148.0.7778.96. Users browsing the web with a vulnerable Chrome installation are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8 and is classified as Medium severity by Chromium. Because it requires an attacker to embed crafted HTML and the exploitation must happen within the sandbox, the likelihood of real‑world exploitation is moderate. It is not listed in the CISA KEV catalog, and its EPSS score is < 1%.
OpenCVE Enrichment
Debian DSA