Impact
A use‑after‑free flaw exists in the compositing subsystem of Google Chrome before version 152.0.7977.82. The vulnerability is limited to the renderer process; a crafted HTML page can harvest the freed memory only after the attacker has already compromised that process. Once triggered, the flaw allows the attacker to execute arbitrary code outside the renderer sandbox, potentially giving full control over the affected system. The weakness is documented as CWE‑416.
Affected Systems
Any instance of Google Chrome older than 152.0.7977.82 is vulnerable. The issue resides in the renderer process’s compositing path and exploits can be triggered by compromised renderer instances in affected browser releases.
Risk and Exploitability
The flaw carries a high security severity according to Chromium but requires an attacker to first compromise the renderer process, which typically involves a prior sandbox escape or direct injection. The CVSS score is 8.3, indicating a high severity. No EPSS score is available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Because the flaw results in code execution outside the sandbox, the potential impact is total system compromise if the vulnerability is successfully triggered.
OpenCVE Enrichment
Debian DLA
Debian DSA