Impact
The vulnerability is a use‑after‑free in the Contextual Tasks component of Google Chrome. When a remote attacker has already compromised the renderer process, they can present a specially crafted HTML page that triggers this flaw, allowing execution of arbitrary code outside the browser sandbox. This is a CWE‑416 weakness and can compromise confidentiality, integrity and availability of the user’s environment.
Affected Systems
The flaw affects Google Chrome on Windows running versions prior to 154.0.8037.97. The attack leverages a defect in the renderer‑side Contextual Tasks feature.
Risk and Exploitability
The issue carries a high severity rating and can lead to arbitrary code execution beyond the sandbox. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, an attacker must first compromise the renderer process—potentially through another browser or system vulnerability—before exploiting the use‑after‑free. Once that precondition is met, exploitation is straightforward via a crafted HTML page. The overall risk to affected systems remains significant.
OpenCVE Enrichment