Impact
The vulnerability is a use‑after‑free flaw located in the DevTools component of Google Chrome versions prior to 152.0.7977.65. It permits a remote attacker to trigger arbitrary code execution within the browser sandbox after the victim installs a specially crafted Chrome extension. This is a high‑severity flaw, with a CVSS score of 8.8, as assessed by Chromium, with weakness classified as CWE‑416.
Affected Systems
The affected product is Google Chrome. All releases before 152.0.7977.65 are vulnerable. Users on stable channel versions earlier than this should apply the update.
Risk and Exploitability
The flaw, with a CVSS score of 8.8, can be exploited by an attacker who successfully convinces a user to install a malicious extension. Since the attack occurs in the local user context, it requires social engineering. No public exploit is documented and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The possibility of sandbox escape and arbitrary code execution makes it a significant risk for users who install untrusted extensions.
OpenCVE Enrichment
Debian DLA
Debian DSA