Impact
A use‑after‑free flaw exists in the Bluetooth implementation of Google Chrome prior to version 152.0.7977.65. The vulnerability allows an attacker to craft a malicious Chrome extension that, through social engineering, can execute arbitrary code outside the browser sandbox. The weakness is identified as CWE‑416.
Affected Systems
The vulnerability affects Google Chrome browsers older than 152.0.7977.65. End users running these versions are potentially exposed if they install malicious extensions or are tricked into enabling them.
Risk and Exploitability
Because the flaw requires the attacker to supply a malicious extension, the attack vector is remote but relies on user interaction or social engineering. Exploitation would allow code execution with privileges higher than those of the sandbox. The EPSS score is 0.00278 (less than 1%) and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of active exploitation but a high severity risk due to the remote nature of the flaw. The CVSS score of 8.8 indicates high severity.
OpenCVE Enrichment
Debian DLA
Debian DSA