Impact
A use‑after‑free flaw in Chrome’s Views component allows a remote attacker that has lured a user to open a crafted HTML page to execute arbitrary code outside the browser sandbox. The vulnerability is a CWE‑416 issue that can be exploited by code running within the Chrome process, granting it the same privileges as the user who viewed the malicious page.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected. No specific sub‑versions are listed beyond the release number. Users of earlier Chrome releases are vulnerable.
Risk and Exploitability
The flaw has a CVSS score of 9.6, indicating high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires social engineering to obtain user interaction with a malicious HTML page. Once the attacker achieves this, they can run code with the same privileges as the browser, potentially compromising the host system.
OpenCVE Enrichment
Debian DLA
Debian DSA