Impact
A use‑after‑free bug in the Media rendering component of Google Chrome for Windows allows a maliciously crafted HTML page to execute arbitrary code while the browser is running. The flaw, identified as CWE‑416 and CWE‑825, enables an attacker to break out of the browser sandbox and run code that could potentially compromise the underlying operating system or user data.
Affected Systems
This vulnerability affects the Windows desktop edition of Google Chrome before version 148.0.7778.216. Any user running an affected Chrome build would be exposed.
Risk and Exploitability
The CVE carries a high severity rating with a CVSS score of 8.8 and is listed as not exploitable in the CISA KEV catalog, with no EPSS score available. The attack vector is inferred to be a remote, user‑initiated attack where an attacker hosts a malicious HTML page and persuades a victim to open it in Chrome. Once the page loads, the use‑after‑free can be triggered, allowing code to execute with browser‑level privileges, and potentially escalating to full system compromise if sandbox boundaries are broken.
OpenCVE Enrichment