Impact
A use-after-free flaw in the DevTools component of Google Chrome is triggered when a crafted Chrome extension is loaded. The bug allows a remote attacker to execute arbitrary code within the browser sandbox, potentially compromising the security of the user’s system. The vulnerability is categorized as a memory corruption issue, identified as CWE-416 and rated Medium in Chromium’s internal severity assessment.
Affected Systems
The issue affects Google Chrome versions prior to 152.0.7977.65. Any user who has a vulnerable version of Chrome installed and who installs a malicious or social‑engineering–crafted extension is at risk. No specific operating systems are listed, so all platforms where the vulnerable Chrome build runs are impacted.
Risk and Exploitability
The EPSS metric is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating it has not been widely exploited in the wild yet. The CVSS score is 8.8, indicating high severity. However, the path to exploitation requires that an attacker successfully persuade a user to install a malicious extension. Based on the description, it is inferred that the attacker would use social engineering to achieve a user‑initiated installation. Once installed, the exploit can run arbitrary code inside the sandbox, which may be leveraged for further compromise depending on the sandbox escapes that may be available in later stages.
OpenCVE Enrichment
Debian DLA
Debian DSA