Impact
A use‑after‑free flaw exists in the Chromoting component of Google Chrome for Windows. The vulnerability allows a remote attacker to craft network traffic that causes the browser to execute code outside its sandbox, giving the attacker full control of the affected system. The weakness is a classic memory‑management error, classified as CWE‑416.
Affected Systems
Google Chrome versions on Windows prior to 152.0.7977.65 contain the bug. Systems running the affected releases are at risk when the Chromoting component is reachable via external traffic.
Risk and Exploitability
The flaw can be exploited remotely without local user interaction or elevated privileges. The CVSS score of 8.1 indicates high severity, while an EPSS score of < 1 % shows a very low likelihood of wild exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Any device that hosts the vulnerable Chrome release and allows inbound traffic can be targeted.
OpenCVE Enrichment
Debian DLA
Debian DSA