Impact
A use‑after‑free flaw in the Views component of Google Chrome enables a remote attacker who lures a user to open a crafted HTML page to execute arbitrary code outside of Chrome’s sandbox. The vulnerability permits exploitation of a freed memory area, potentially allowing the attacker to run code with the user’s privileges and bypass normal browser isolation. The flaw is considered medium‑severity by Chromium’s own assessment, but the impact could be far more severe if the attacker can successfully bypass sandbox constraints.
Affected Systems
Google Chrome versions before 152.0.7977.65 are affected. The defect exists in the stable channel; any user running a version of Chrome below the specified release is vulnerable and must upgrade to the patched build or later.
Risk and Exploitability
The EPSS score for this vulnerability is not available, and it is not listed in the CISA KEV catalog, suggesting limited or no public exploitation yet. However, the CVSS score of 9.6 indicates high severity, and the use‑after‑free flaw can break sandbox isolation, meaning exploitation is theoretically possible. The likely attack vector is social engineering: a malicious actor sends a phishing message containing a specially crafted HTML file that, when opened, triggers the flaw. Given the lack of a publicly known exploit and the pending patch, the current risk is high but should be mitigated promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA