Impact
The vulnerability is a use‑after‑free flaw in the Chromoting component of Google Chrome that allows a remote attacker who can inject specially crafted packets to execute arbitrary code outside the browser sandbox. This could result in full system compromise, data theft, or installation of additional malware. The weakness corresponds to CWE‑416 and is classified as a medium‑severity issue by Chromium security.
Affected Systems
Affected systems are Google Chrome browsers older than version 152.0.7977.65. Users of the stable channel who have not yet upgraded to the patched release are potentially exposed.
Risk and Exploitability
The CVSS score is 8.1, and the EPSS score is < 1%, indicating high technical severity but very low probability of exploitation. Chromium rates the flaw as medium severity. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting limited or no known active exploitation. Based on the description, the attack vector appears to be via crafted network traffic directed at the Chromoting protocol, implying a network‑based remote attack that requires proximity to the user’s machine and the ability to inject or manipulate packets.
OpenCVE Enrichment
Debian DLA
Debian DSA