Impact
This vulnerability is a use‑after‑free flaw in the Federated Credential Management (FedCM) API of Google Chrome. A crafted HTML page may trigger a memory corruption that allows a remote attacker to execute arbitrary code outside the browser sandbox. The flaw is rated high in Chromium’s internal severity, indicating that a successful exploitation could compromise system confidentiality and integrity.
Affected Systems
Google Chrome versions released before 152.0.7977.65 contain the affected FedCM implementation. Users of the stable channel of Chrome prior to that build are impacted.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 9.6 indicates a critical severity, which aligns with the high internal severity assessment. The likely attack vector is a social‑engineering attack that delivers a malicious web page to a user. An attacker who succeeds in exploiting the use‑after‑free can bypass the browser sandbox and run code with the privileges of the browser process.
OpenCVE Enrichment
Debian DLA
Debian DSA