Impact
A use‑after‑free flaw in the FedCM implementation of Google Chrome allows a remote attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. The vulnerability, rated high by Chromium, could compromise confidentiality, integrity, and availability of the affected system if an unprivileged web page triggers the exploit.
Affected Systems
Google Chrome users who have not upgraded to version 154.0.8037.97 or later are affected. The flaw exists in all prior releases of Chrome and can impact any user visiting a site that can deliver a malicious HTML payload to the browser.
Risk and Exploitability
The vulnerability carries a high severity rating by Chromium. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. However, the potential for remote code execution outside the sandbox underscores a significant risk if an attacker can deliver a crafted page to the user. The likely attack vector is a remotely hosted malicious website that triggers the use‑after‑free condition during FedCM processing.
OpenCVE Enrichment