Impact
A use‑after‑free flaw (CWE‑416) in Chrome’s Views component can let a compromised renderer process run code outside the browser sandbox. Based on the description, it is inferred that a maliciously crafted HTML page can trigger the flaw by causing the renderer to free an object and subsequently use it. When triggered, the attacker can execute arbitrary code with the privileges of the renderer, which are normally restricted by the sandbox but can be bypassed, leading to potential full system compromise.
Affected Systems
Google Chrome builds older than 152.0.7977.65 on all platforms are affected. The bug resides in the default renderer configuration, so users running those builds and allowing untrusted web content remain vulnerable.
Risk and Exploitability
Chromium lists the defect with medium severity internally, yet the CVSS score of 8.3 indicates a high risk. The EPSS score of 0.00518 indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread publicly known exploits yet. The attacker must be able to load malicious content into Chrome’s renderer; once this precondition is met, the bug provides remote code execution that can escape the sandbox. The combination of a high CVSS score and the potential for full‑system compromise warrants immediate attention.
OpenCVE Enrichment
Debian DLA
Debian DSA