Impact
A use‑after‑free flaw exists in the TabStrip component of Google Chrome versions older than 152.0.7977.75. By provoking a freed memory reference through a crafted user‑interface interaction, a remote attacker can execute arbitrary code outside the browser sandbox. This error gives the attacker full read‑write capability on the machine, enabling credential theft, data exfiltration, or system compromise.
Affected Systems
Any desktop installation of Google Chrome that has not been updated to 152.0.7977.75 is vulnerable. The issue is present in the stable channel and applies across all operating systems that run the affected Chrome build.
Risk and Exploitability
Chromium rated the vulnerability as low severity and it is not listed in CISA’s KEV catalog. No EPSS score is available, indicating that exploitation is not known to be widespread. The attack requires a social‑engineering step to convince a user to interact with the crafted interface, so it is not a simple network‑based exploit. Nevertheless, if an attacker succeeds, the ability to run code outside the sandbox poses a high risk to confidentiality, integrity, and availability on the target system.
OpenCVE Enrichment