Impact
This vulnerability is a use‑after‑free bug found in the DevTools component of Google Chrome. A crafted HTML page can trigger the fault and allow a remote attacker to execute arbitrary code outside the browser sandbox, giving full control over the system. The weakness is categorized as CWE‑416. Since the flaw allows code execution, it presents a significant confidentiality, integrity, and availability risk to any user who visits a malicious page.
Affected Systems
All installations of Google Chrome older than version 152.0.7977.82 are affected. The issue reports the use‑after‑free occurring in DevTools before that release, so any browser running a version prior to 152.0.7977.82 is vulnerable.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity level, consistent with Chromium's assessment. No EPSS score is available, and it is not listed in the CISA KEV catalog, but the potential to run code outside the sandbox makes it a critical threat. Exploitation requires a malicious HTML page that is opened by a user; once the page loads, an attacker can trigger the DevTools use‑after‑free and run arbitrary code. The attack vector is remote via a crafted web page that a user visits or opens in the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA