Impact
A use‑after‑free flaw in Chrome’s Compositing engine allows a remote attacker to run arbitrary code inside the sandbox via a crafted HTML page. The weakness is a type of resource misuse that corrupts heap memory, enabling code execution once the page is rendered. The impact is the ability to execute code with the sandbox’s privileges, potentially allowing an attacker to compromise user data or attempt to escape the sandbox to affect the host system.
Affected Systems
Google Chrome browsers running versions prior to 152.0.7977.65 are affected. No other products or vendors are listed as impacted.
Risk and Exploitability
The vulnerability can be triggered from any webpage supplied to the browser, so an attacker can target users through normal browsing or phishing. The CVSS score of 8.8 indicates a high severity, and although its EPSS score is not available, the potential for remote code execution is significant. The CVE is not listed in CISA’s KEV catalog, but the high risk level urges organizations to patch or otherwise protect affected systems promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA