Impact
The vulnerability is a use‑after‑free in the Animation module of Google Chrome, allowing a remote attacker to execute arbitrary code within the browser’s sandbox by delivering a specially crafted HTML page. Because the flaw occurs during page rendering, an attacker could compromise the sandbox boundaries and potentially escape to the host system, though the attack is constrained to the sandboxed process. The issue is rated low severity by Chromium.
Affected Systems
This flaw affects installations of Google Chrome versions older than 152.0.7977.65, regardless of operating system. Users running the affected version should upgrade to the patched release or newer, which removes the use‑after‑free condition in the Animation component.
Risk and Exploitability
There is no publicly available EPSS score and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.8 indicates a high severity issue. Even though exploitation is confined to the browser sandbox, the high score reflects the risk that an attacker can execute arbitrary code within the sandboxed process by delivering a crafted HTML page. The attack requires the victim to view the malicious page and is most dangerous for users who run web content from untrusted sources.
OpenCVE Enrichment
Debian DLA
Debian DSA