Impact
This vulnerability is a use‑after‑free in the WebGL implementation of Google Chrome. A crafted WebGL context can trigger an invalid free, allowing an attacker to execute arbitrary code outside the browser sandbox, thereby compromising confidentiality, integrity, and availability on the victim’s machine. The weakness is classified as CWE‑416 and is identified as a high‑severity flaw by the Chromium security team.
Affected Systems
Google Chrome browsers built on the Chromium engine are affected. Versions older than 152.0.7977.65 are vulnerable, while the 152.0.7977.65 release and later contain the fix.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, so the current exploitation probability is uncertain. The flaw allows remote code execution when a victim loads a malicious webpage that activates the WebGL bug; no additional privileges are required beyond normal browsing rights. The impact is high, as the code runs outside the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA