Impact
Google Chrome versions prior to 152.0.7977.75 contain a use‑after‑free bug in the browser component that can be triggered by a malicious HTML page. If a remote attacker has already compromised the renderer process, this flaw allows execution of arbitrary code outside the sandbox, with severity classified as high.
Affected Systems
The vulnerability affects users running Google Chrome, specifically versions earlier than 152.0.7977.75. All users of the stable channel before the September 2026 release are impacted.
Risk and Exploitability
The exploitation requires control over the renderer process, which implies that an attacker must first compromise the browser environment. Because the bug permits code execution outside the sandbox, the impact can be system‑wide. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog; however, the high severity rating and the ability to escape sandbox boundaries indicate a significant risk if the attacker can achieve the initial renderer compromise.
OpenCVE Enrichment