Impact
Use‑after‑free in WebAudio allows a remote attacker to craft a malicious HTML page that triggers a memory corruption bug, enabling execution of arbitrary code inside Chrome’s sandbox. The flaw is a classic CWE‑416 vulnerability that could give an attacker full control over the victim’s browser process.
Affected Systems
The affected product is Google Chrome on all platforms for versions prior to 148.0.7778.96. Users browsing the web with a vulnerable Chrome installation are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8 and is classified as Medium severity by Chromium. Because it requires an attacker to embed crafted HTML and the exploitation must happen within the sandbox, the likelihood of real‑world exploitation is moderate. No evidence suggests it is in the CISA KEV catalog or has an EPSS score at this time.
OpenCVE Enrichment
Debian DSA