Impact
This vulnerability is a use‑after‑free bug in the Aura component of Google Chrome that allows a crafted HTML page to cause Chrome to execute arbitrary code outside its sandbox. The bug can result in a complete compromise of the victim’s system, exposing confidential data or allowing further exploitation.
Affected Systems
It affects all installations of Google Chrome before version 152.0.7977.65. Users of any earlier Chrome release are potentially vulnerable.
Risk and Exploitability
The issue carries a CVSS score of 9.6, classified as Critical by Chromium. An attacker can exploit it remotely by convincing a user to open a malicious HTML file or visit a malicious website. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high severity indicates a potentially serious risk if not patched.
OpenCVE Enrichment
Debian DLA
Debian DSA