Impact
The flaw is a use‑after‑free in Chrome’s HTML parser that allows an attacker to execute arbitrary code with the same privileges as the renderer process. The vulnerability is classified as CWE‑416 and has a CVSS score of 8.8. The exploit can be triggered by delivering a crafted HTML page to a user, resulting in code execution confined initially to the sandboxed environment.
Affected Systems
All Chrome releases prior to 155.0.8059.39 on desktop platforms are affected. The description indicates that the issue applies to the stable channel on Windows, macOS, and Linux, which is inferred from the mention of desktop platforms and the stable channel update in the advisory.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the high CVSS indicates significant risk. Attackers can embed malicious content in emails, websites, or local files, requiring user interaction to load the crafted page. Once exploited, the attacker obtains sandboxed code execution, which could lead to privilege escalation if the sandbox is bypassed. No public exploit code is documented, but the threat remains serious for users of outdated Chrome.
OpenCVE Enrichment