Impact
A use‑after‑free bug in the WebRTC component of Google Chrome versions prior to 152.0.7977.75 allows a remote attacker to execute arbitrary code inside the sandbox by serving a crafted HTML page. This flaw is a classic instance of CWE‑416, which enables code execution with the same privileges as the browser process, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Google Chrome on all platforms is affected. Any installation of Chrome earlier than 152.0.7977.75 is vulnerable. The issue is present in desktop builds of the stable channel and likely in older beta and dev channels that have not been upgraded to the patched version.
Risk and Exploitability
The vulnerability can be triggered remotely from a malicious web page, meaning an attacker only needs to lure a user to a crafted site. Although the EPSS score is not currently available and the vulnerability is not in the CISA KEV catalog, the medium severity rating from Chromium and the potential for full code execution imply a high impact if exploited. The lack of an existing workaround suggests that the exploitability is effectively high until a patch is applied.
OpenCVE Enrichment