Impact
This vulnerability is a use-after-free flaw in the Views component of Google Chrome prior to 152.0.7977.65. An attacker who lures a user to a specially crafted web page can cause the browser to run code outside its sandbox, giving the attacker arbitrary code execution.
Affected Systems
Google Chrome releases prior to 152.0.7977.65 are affected; that includes all patch levels before that specific revision.
Risk and Exploitability
The flaw has a CVSS score of 9.6, indicating a critical severity, though no EPSS score is available and it is not listed in the CISA KEV catalog. The exploit requires social engineering to convince a user to visit a malicious page, so it is less likely than a purely remote attack, but successful execution would allow the attacker to run code with the privileges of the application.
OpenCVE Enrichment
Debian DLA
Debian DSA