Impact
A use-after-free condition in Chromecast functionality within Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox by delivering a crafted HTML page. This flaw is a classic memory corruption weakness (CWE‑416) and also maps to an improper resource operation weakness (CWE‑825), compromising the confidentiality, integrity, and availability of the affected system by running malicious payloads with reduced privileges but still capable of bypassing sandbox restrictions.
Affected Systems
All users running Google Chrome versions earlier than 153.0.8010.36 are vulnerable. The issue impacts the native Chromecast component used for media casting and is present in the Chrome stable channel on desktop platforms.
Risk and Exploitability
Because the vulnerability requires a crafted HTML page and can be triggered remotely, it can be exploited by a malicious website or phishing email that loads the page in Chrome. The CVSS score of 8.8 indicates high severity, but the EPSS score is not reported; the flaw is not listed in the CISA KEV catalog. Inferred attack scenarios involve a malicious web actor hosting a specially crafted page, exploiting the out‑of‑bounds access to trigger code execution within the sandbox. The lack of a publicly disclosed exploit means the current threat level is moderate, yet the ability to achieve remote code execution warrants prompt mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA