Impact
The vulnerability is a use‑after‑free flaw (CWE-416) in Chrome’s Aura component, allowing a remote attacker to execute arbitrary code outside the sandbox by serving a specially crafted HTML page.
Affected Systems
Any installation of Google Chrome that runs version 152.0.7977.64 or earlier is affected.
Risk and Exploitability
Chromium reports the flaw with a CVSS score of 9.6, indicating critical severity. No exploitation probability is available, and it is not yet listed in CISA’s KEV catalog. The flaw can be leveraged by delivering a malicious web page, giving the attacker full control over a confirmed user’s machine without sandbox restrictions.
OpenCVE Enrichment
Debian DLA
Debian DSA