Impact
The flaw is a use‑after‑free bug in Google Chrome’s Extensions component. A crafted extension can trigger a freed memory reference that may lead to the execution of arbitrary code outside Chrome’s sandbox. The affected code paths allow the attacker to run malicious instructions with the privileges of the user’s Chrome process, potentially escalating privileges on the underlying system.
Affected Systems
Google Chrome before version 152.0.7977.65 is affected. All desktop platforms running those releases can be compromised, once a malicious extension is installed.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.6, reflecting a high severity rating. Exploitation requires the user to install or update a malicious extension, so social engineering is the primary attack vector. An EPSS score of 0.00278 (≈0.28%) indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog; nevertheless, the lack of protection against this use‑after‑free still represents a significant risk to any installation of Chrome prior to the stated patch.
OpenCVE Enrichment
Debian DLA
Debian DSA