Impact
A use‑after‑free bug in the Chrome user interface allows a local attacker who has already compromised the renderer process to execute arbitrary code outside the browser’s sandbox. The flaw is triggered when the renderer performs an invalid memory dereference after freeing the UI object, giving the attacker control of the process.
Affected Systems
The vulnerability affects Google Chrome on all platforms before version 152.0.7977.65. Users running any earlier Chrome release are exposed.
Risk and Exploitability
Because the attack requires local access to a compromised renderer process, the attack surface is limited to the victim’s machine. The EPSS score of <1% indicates a very low exploitation probability. The CVSS score of 7.7 indicates medium severity, and no exploitation data or KEV listing is available at this time. Nonetheless, the possibility of arbitrary code execution warrants immediate attention and patching.
OpenCVE Enrichment
Debian DLA
Debian DSA