Impact
The vulnerability is a use-after-free condition in Chrome's rendering views that can be triggered by a specially crafted HTML page. It allows a remote attacker to execute arbitrary code outside the browser sandbox. The weakness exploited is a memory-safety flaw classified as CWE-416, leading to complete loss of isolation between the browser process and the system.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 on all platforms are affected. Users running any version prior to that revision of Chrome are at risk until they apply the vendor update.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity, confirming the critical danger posed by this vulnerability, and the flaw is considered a remote code execution vector. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply a malicious HTML page, so the attack is remote and can be performed over the internet. Because of the lack of a sandbox escape bypass, the attack vector relies on DOM manipulation and the use of the freed memory area.
OpenCVE Enrichment
Debian DLA
Debian DSA