Impact
A use‑after‑free flaw was discovered in the Platform component of Google Chrome versions earlier than 152.0.7977.65. The bug permits a remote attacker to trigger the freed memory usage through a crafted HTML document, enabling execution of arbitrary code within the browser’s sandbox. The underlying weakness to CWE‑416, which can lead to code execution and compromise of the sandboxed environment, potentially exposing confidential data or allowing further lateral movement in the host environment.
Affected Systems
The affected product is Google Chrome for desktop users. Any Chrome installation running a version earlier than 152.0.7977.65 is vulnerable. Updated releases from version 152.0.7977.65 onward contain the fix.
Risk and Exploitability
Chromium classifies this vulnerability with a high severity rating and assigns a CVSS score of 8.8. Because the flaw can be triggered via a web page, the attacker’s threat vector is network‑based, requiring the victim to view a malicious page in the browser. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. However, the combination of a high severity classification and a remote network trigger suggests a considerable risk to users who routinely browse the Internet.
OpenCVE Enrichment
Debian DLA
Debian DSA