Impact
A use‑after‑free vulnerability in the SVG parser of Google Chrome versions before 154.0.8037.97 permits a remote attacker to execute arbitrary code inside the browser sandbox through a specially crafted HTML page. This flaw, categorized as CWE‑416, enables attackers to run code with the limited permissions of the browser’s sandbox environment, potentially compromising the client system or user data if the sandbox is escaped.
Affected Systems
The bug affects Google Chrome across all platforms (Windows, macOS, Linux) for versions earlier than 154.0.8037.97. Users running any older build are vulnerable until they install a later release that includes the fix.
Risk and Exploitability
Although the CVSS score is not provided, the vulnerability is rated high in Chromium’s severity assessment. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, indicating no publicly known exploits. The attack vector is inferred to be a malicious web page that a user visits; the attacker can embed crafted SVG content within that page to trigger the use‑after‑free. Exploitation requires that the victim open the malicious page, meaning the risk is mitigated by user behavior and browser update status.
OpenCVE Enrichment