Impact
Google Chrome has a use‑after‑free vulnerability affecting the Script module in versions prior to 152.0.7977.65. A remote attacker can supply a specially crafted HTML page that triggers the flaw and allows arbitrary code to run within the browser sandbox. Because the execution occurs in the sandbox, the attacker can modify or read browsing data, inject malicious scripts, or potentially escape the sandbox if additional flaws exist. The Chromium team classified it as a high‑severity issue.
Affected Systems
The vulnerability applies to the Google Chrome desktop browser running any version earlier than 152.0.7977.65. All users of the stable channel who have not yet updated to the 152.0.7977.65 release or newer are affected.
Risk and Exploitability
EPSS scores are not available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the flaw permits remote code execution via a malicious web page that a user can open or be redirected to. The CVSS score of 8.8 indicates high severity, and the risk to users remains significant until the patch is applied. The exploit can be triggered by a user visiting an attacker‑controlled site or by a drive‑by‑download of malicious content.
OpenCVE Enrichment
Debian DLA
Debian DSA