Impact
Google Chrome contains a use‑after‑free flaw in its WebRTC implementation that allows an attacker to execute arbitrary code within the browser’s sandbox. This vulnerability permits remote exploitation through a crafted HTML page and can lead to running malicious code with the permissions granted to the sandboxed process. The weakness is identified as CWE‑416 and CWE‑825.
Affected Systems
Versions of Google Chrome before 148.0.7778.216 are affected. Updating to this revision or any newer release removes the vulnerability.
Risk and Exploitability
The vulnerability carries a Chromium security severity of High and a CVSS score of 8.8, and permits remote code execution via a web page. The EPSS score is <1%, indicating a very low but nonzero probability of exploitation, and the issue is not listed in the CISA KEV catalog. Attackers can target users by hosting a malicious site that delivers the exploit, making the risk significant for any user who visits web content without additional mitigations.
OpenCVE Enrichment