Impact
A use‑after‑free flaw in the Chrome proxy component allowed a remote attacker to craft network traffic that could cause Chrome to execute arbitrary code outside its sandbox. The bug exploits a dangling pointer that persists after the proxy object is freed, enabling memory corruption and code execution with system privileges. The consequent impact is the ability to run malicious code on the user’s machine without sandbox restrictions, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects Google Chrome desktop releases prior to version 152.0.7977.75. Any machine running one of those older Chrome versions is vulnerable when it processes crafted network traffic through the proxy subsystem.
Risk and Exploitability
Chromium classifies this as a high‑severity issue. While an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation remains elevated because the flaw can be triggered remotely via network traffic. The attack vector is inferred to require an attacker to send specially crafted packets to the Chrome proxy, making the threat most relevant to systems exposed to potentially malicious network traffic.
OpenCVE Enrichment