Impact
The vulnerability is a use‑after‑free in the Chromoting component of Google Chrome for Windows. Once an attacker has already compromised the renderer process, the attacker can send specially crafted network traffic that frees a memory object and then accesses it, allowing execution of arbitrary code outside the browser sandbox. The primary impact is remote code execution that can lead to full system compromise.
Affected Systems
Google Chrome on Windows versions prior to 152.0.7977.65. The issue affects any machine running the affected Chrome release on the Windows platform.
Risk and Exploitability
The Chromium security severity is rated High with a CVSS score of 8.3. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, making the overall exploit probability difficult to quantify. However, the requirement of a renderer‑process compromise and crafted network traffic indicates a high technical barrier. The likely attack vector is a remote attacker exploiting crafted traffic after a renderer compromise to execute code outside the sandbox, potentially gaining system‑level control.
OpenCVE Enrichment
Debian DLA
Debian DSA