Impact
A use‑after‑free bug exists in the Aura graphics layer of Google Chrome. When an attacker loads a specially crafted HTML page, the browser can free an object that is still referenced, allowing execution of arbitrary code outside the renderer sandbox. The flaw is classified as CWE‑416 and was rated as high severity by Chromium’s internal reviewers.
Affected Systems
This issue affects the Google Chrome desktop browser. Versions prior to 152.0.7977.65 are vulnerable. The fix is supplied in Chrome release 152.0.7977.65 and later.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity. The flaw remains a remote code‑execution vector that allows a crafted HTML page to free an object still referenced and execute code outside the renderer sandbox. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. While no public exploitation reports exist yet, the attack can be triggered by any untrusted HTML content, so systems running an affected Chrome version remain at significant risk until a patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA