Impact
Chrome users run a critical use‑after‑free bug in the Aura rendering engine that can be triggered by a crafted HTML page. The flaw allows a remote attacker to execute arbitrary code outside the browser sandbox, leading to full system compromise. This is an instance of CWE‑416 use‑after‑free, where a pointer to freed memory is accessed, enabling code execution.
Affected Systems
All Google Chrome installations are vulnerable if they are running a version earlier than 152.0.7977.65. The affected component is the Aura rendering subsystem, which is part of the Chrome browser distributed by Google.
Risk and Exploitability
The CVSS score of 9.6 classifies this vulnerability as critical, indicating a potential for complete system compromise. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a maliciously crafted web page delivered over the network; an attacker can host such a page or embed it in phishing media. Because the vulnerability is remote and sandbox‑breaking, the potential impact is full system compromise for the local user.
OpenCVE Enrichment
Debian DLA
Debian DSA