Impact
A use-after-free flaw was discovered in the Accessibility module of Google Chrome prior to version 152.0.7977.65. The vulnerability allows a remote actor, using social engineering, to trigger a UI interaction that causes the browser to access freed memory. This can lead to the execution of arbitrary code outside the sandbox. The flaw is categorized as a memory corruption issue (CWE-416).
Affected Systems
The affected product is Google Chrome. Any Chrome installation with a version older than 152.0.7977.65 is vulnerable, regardless of operating system. The vulnerability is associated with the Accessibility domain of the browser.
Risk and Exploitability
The flaw carries a high severity rating from Chromium, indicating significant risk. The CVSS score of 8.8 confirms the high severity of this vulnerability. While the EPSS score is < 1%, the lack of a listing in the CISA KEV catalog suggests no widespread exploitation has been reported to date. The attack requires a social engineering vector that encourages the target user to interact with a crafted UI element, making it a user‑interactive remote code execution vector. Despite these prerequisites, the potential to escape the sandbox and run arbitrary code makes the risk substantial for any user who accepts such interactions.
OpenCVE Enrichment
Debian DLA
Debian DSA